<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Mark+A.+Arnold</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Mark+A.+Arnold"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Mark_A._Arnold"/>
		<updated>2026-05-31T15:40:34Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=2010_BASC_Speakers&amp;diff=93356</id>
		<title>2010 BASC Speakers</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=2010_BASC_Speakers&amp;diff=93356"/>
				<updated>2010-11-19T21:24:22Z</updated>
		
		<summary type="html">&lt;p&gt;Mark A. Arnold: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{2010_BASC:Header_Template | Speakers/Panelists}}&lt;br /&gt;
__FORCETOC__&lt;br /&gt;
We would like to thank our speakers for donating their time and effort to help make this conference successful.&lt;br /&gt;
&lt;br /&gt;
=== Josh Corman === &lt;br /&gt;
'''The 451 Group'''&amp;lt;br/&amp;gt;&lt;br /&gt;
''Panelist''&amp;lt;br /&amp;gt;&lt;br /&gt;
Joshua Corman is the Research Director of the 451 Group's enterprise security practice. Corman has more than a decade of experience with security and networking software, most recently serving as Principal Security Strategist for IBM Internet Security Systems. Corman’s research cuts across sectors to the core challenges of the industry, and drives evolutionary strategies toward emerging technologies and shifting economics. Corman is a candid and highly coveted speaker and has spoken at leading industry events such as RSA, Interop, ISACA, and SANS. His efforts to educate and challenge the industry recently lead NetworkWorld magazine to recognize him as a [http://www.networkworld.com/supp/2009/outlook/010509-tech-people-to-know.html top innovators of IT] for 2009. Corman also serves on the Faculty for IANS and is a staunch advocate for CISOs everywhere. In 2010, Corman also co-founded [http://rugedsoftware.org RuggedSoftware.org] – a value based initiative to raise awareness and usher in an era of secure digital infrastructure.&lt;br /&gt;
&lt;br /&gt;
=== Ming Chow ===&lt;br /&gt;
'''Tufts University, CS Department'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Ming Chow is a scholar of science and technology and a Lecturer at the Tufts University Department of Computer Science.  His areas of interests are computer security, game development, web application security, and Computer Science in Education. Ming co-edited a special issue of IEEE Security &amp;amp; Privacy on securing online games with Gary McGraw of Cigital, Inc. published in May 2009. Ming is a frequent guest speaker, and have spoke at numerous organizations, including New England Association of Insurance Fraud Investigators (NEAIFI), and the New England Chapter of the High Technology Crime Investigation Association (HTCIA-NE), the Greater Boston Chapter of the Association of Certified Fraud Examiners (ACFE), John Hancock, and the Massachusetts Office of the Attorney General (AGO). Finally, Ming is a SANS GIAC Certified Incident Handler (GCIH).&lt;br /&gt;
&lt;br /&gt;
=== Andrew Gronosky  ===&lt;br /&gt;
'''Raytheon/BBN Technologies'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Mr. Andrew Gronosky is a staff engineer at Raytheon BBN Technologies. He has experience developing software for a variety of applications including data analysis and visualization, digital signal processing, and parallel and distributed systems. He holds a Master of Science degree in mathematics from Rensselaer Polytechnic Institute and is a member of the IEEE and the ACM. &amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Joshua &amp;quot;Jabra&amp;quot; Abraham, Will Vandevanter  ===&lt;br /&gt;
'''Rapid7'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Joshua &amp;quot;Jabra&amp;quot; Abraham joined Rapid7 in 2006 as a Security Consultant. Josh has extensive IT Security and Auditing experience and worked as an enterprise risk assessment analyst for Hasbro Corporation. Josh specializes in penetration testing, web application security assessments, wireless security assessments, and custom code development. He has spoken at BlackHat, DefCon, ShmooCon, The SANS Pentest Summit, Infosec World, CSI, OWASP Conferences, LinuxWorld, Comdex and BLUG. In his spare time, he contributes code to open source security projects such as the BackTrack LiveCD, BeEF, Nikto, Fierce, and PBNJ. He is frequently quoted in the media regarding Microsoft Patch Tuesday and web application security by ComputerWorld, DarkReading and SC Magazine.&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
Mr. Vandevanter joined Rapid7 in 2008. Will has IT Security experience with a focus in web application security and secure software engineering. Will specializes in penetration testing, web application security assessments, and secure code development. In the past Will has also worked on a few different Open Source security projects including porting SELinux to OpenMoko and other Linux based mobile platforms. Will holds a Bachelors Degree in Mathematics and Computer Science from McGill University and Masters Degree in Computer Science from James Madison University.&lt;br /&gt;
&lt;br /&gt;
=== Christien Rioux  ===&lt;br /&gt;
'''SOURCE Conference/Veracode'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Christien Rioux is co-founder and chief scientist of Veracode, the world's only binary-analysis powered online application risk management service. Prior to Veracode, he was a founder at security consulting firm @stake, a member of the hacker think-tank L0pht Heavy Industries, and a graduate of Massachusetts Institute Of Technology.&lt;br /&gt;
Today, he focuses on algorithms to automate the difficult task of reverse-engineering and analyzing binaries for security vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
=== Paul Schofield  ===&lt;br /&gt;
'''Imperva'''&amp;lt;br/&amp;gt;&lt;br /&gt;
With broad business and technical experience ranging from mergers and acquisitions to incident response and investigations, Paul Schofield is a frequent and energetic public speaker.&lt;br /&gt;
With over fourteen years of experience in Information Security and Risk Management, his diverse background he brings insightful perspectives to security and risk management discussions.&lt;br /&gt;
Paul is currently a Senior Security Engineer with Imperva,  an award winning application Security company.&lt;br /&gt;
&lt;br /&gt;
=== Rob Cheyne  ===&lt;br /&gt;
'''Safelight Security Advisors'''&amp;lt;br/&amp;gt;&lt;br /&gt;
''Expert Panel Moderator''&amp;lt;br/&amp;gt;&lt;br /&gt;
Rob is the CEO of Safelight Security, a leading provider of both instructor-led and computer-based security training.  He is a Boston-based information security expert who has taught information security training classes to over ten thousand students, including developers, architects, and managers for industry-leading organizations.  He has 20 years of experience in the information technology field and has been working in information security since 1998. Over the years, he has played the role of software developer, systems integrator, security consultant and trainer.  Rob was a co-founder of @stake, a highly regarded pioneer in information security consulting.  In this role, he led and conducted secure architecture and design reviews, secure code reviews, application penetration tests, security assessments, and training for numerous Fortune 500 companies.  Rob worked on @stake's SmartRisk Analyzer team, building software that automatically scans applications for vulnerabilities, and he was the author of LC4, a version of the award-winning L0phtCrack password auditing tool. @stake was acquired by Symantec Corporation in October 2004.&lt;br /&gt;
Rob regularly speaks at security conferences, and frequently presents to the Boston OWASP chapter on a variety of security topics. His specialties are application security architecture and information security training. &lt;br /&gt;
&lt;br /&gt;
=== John Carmichael  ===&lt;br /&gt;
'''Safelight Security Advisors'''&amp;lt;br/&amp;gt;&lt;br /&gt;
John Carmichael applies his software security expertise to the creation and delivery of world class security training for some of the world’s largest organizations.  At Safelight Security Advisors, he is an integral part of the product team creating best of breed computer-based training courses. Prior to joining Safelight Security Advisors, John was a security trainer and consultant at both Security Innovation and Cigital.  His software security experience is rooted in a background of software development with deep expertise in a myriad of languages and environments.  He has developed enterprise class software for large organizations such as Massachusetts Executive Office of Health and Human Services and Computer Science Corporation. John earned his B.S. degree in Computer Science and Business Administration from the University of Vermont and an M.S. degree in Computer Information System Security from Boston University.&lt;br /&gt;
&lt;br /&gt;
=== Dan Crowley ===&lt;br /&gt;
'''Core Security'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Dan Crowley is an independent security researcher and lecturer also working for Core Security Technologies. Dan runs a security education group called CSEC, which is in the process of becoming a hackerspace. In his free time, he can frequently be found playing with Web-based technologies and locks.&lt;br /&gt;
=== Kenneth Smith ===&lt;br /&gt;
Ken Smith, CISSP, CISA, GCIH is an Enterprise Information Security Architect with 15 years of experience in the information security space.  He currently leads efforts related to IT risk management, compliance, and privacy for a private $1B e-Commerce, Catalog, and Retail organization.  As a consultant, and former QSA, Ken has an extensive background in PCI DSS and has helped many organizations in the area of strategic planning, assessment, remediation plan development, and security program design. &lt;br /&gt;
&lt;br /&gt;
=== Zach Lanier ===&lt;br /&gt;
'''Intrepidus Group'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Zach Lanier is a Senior Security Consultant with the Intrepidus Group, a firm specializing in security assessment services. Zach's areas of focus&lt;br /&gt;
are network and application penetration testing, intrusion analysis, and general hackery, with frequent dabbling in security and privacy research.&lt;br /&gt;
&lt;br /&gt;
=== Shakeel Tufail  ===&lt;br /&gt;
'''Fortify'''&amp;lt;br/&amp;gt;&lt;br /&gt;
''Panelist''&amp;lt;br/&amp;gt;&lt;br /&gt;
Shakeel Tufail is a Federal Practice Manager at Fortify, an HP company, where his responsibilities include refining customer security requirements, managing Fortify product deployments and delivering security services.&lt;br /&gt;
Mr. Tufail brings over 18 years of experience to the IT industry in the areas of network engineering, software development, quality assurance, risk management, and security.&lt;br /&gt;
Recently, he led over 30 enterprise security assessments for DoD and Fortune Top 50 commercial organizations that directly led to improvement of their risk profile.&lt;br /&gt;
Prior to joining Fortify, Mr. Tufail held positions such as Deputy Program Manager for the Pentagon Force Protection Agency, Managing Partner for Insyte, General Manager of CompUSA, and Lead Release Engineer for AOL Time-Warner’s AOL Instant Messenger development team and HOST Servers QA group.&lt;br /&gt;
An active software assurance community member, Mr. Tufail contributes to standards-defining efforts including the Common Weakness Enumeration (CWE), the Common Attack Pattern Enumeration and Classification (CAPEC) and other elements of the Software Assurance Programs of the Department of Homeland Security, NSA, and the Department of Defense. He has accumulated over 25 industry standard certifications and is a member of OWASP, ISACA, ISSA, and IEEE. In his spare time, Shakeel enjoys travel, photography, and technical training at local schools. Recently, he hiked the Himalayas to Mt. Everest BaseCamp.&lt;br /&gt;
&lt;br /&gt;
=== Justin Peavey ===&lt;br /&gt;
'''Omgeo, LLC'''&amp;lt;br/&amp;gt;&lt;br /&gt;
''Panelist''&amp;lt;br/&amp;gt;&lt;br /&gt;
Justin S. Peavey is the Chief Information Security Officer for Omgeo LLC, the market leader in allocation, confirmation/affirmation, settlement notification, enrichment, operational analytics and counterparty risk management services between trade counterparties..  Prior to joining Omgeo, Justin was a VP at State Street performing security architecture and enterprise security program development with a specialization in application security.  Justin has been working in the information security field for over 15 years primarily for the finance and defense industries and has worked with such companies as Lockheed Martin, Pratt &amp;amp; Whitney, Fidelity Investments, John Hancock, IBM Scientific Research Center, and RSA Security. Justin’s background is in security program development, security architecture, software development, and service delivery management.&lt;br /&gt;
&lt;br /&gt;
=== Adriel Desautels ===&lt;br /&gt;
'''NetRagard, LLC'''&amp;lt;br/&amp;gt;&lt;br /&gt;
''Panelist''&amp;lt;br/&amp;gt;&lt;br /&gt;
Adriel T. Desautels is the President and CTO of Netragard, LLC. Among other things Adriel specializes in the delivery of advanced, high-threat anti-hacking services and covert network penetration methodologies. Prior to founding Netragard Adriel founded the internationally recognized SNOsoft Research Team, which quickly became the think tank for Secure Network Operations, Inc. Today SNOsoft is owned and operated by Netragard LLC. Adriel also has extensive experience and expertise in the design and deployment of sophisticated Intrusion Detection and Intrusion Prevention (IDS/IPS) systems. In early 2002 Adriel designed an IDS/IPS technology with powerful event correlation capabilities capable of accurately identifying real events buried in a high volume of noise. That technology was later acquired by a private third party. As a result of his expertise Adriel has acted as an expert witness in U.S. Federal Court. Today Adriel’s responsibilities at Netragard include but are not limited to the design and management of all of Netragard’s professional services. Adriel’s secondary responsibility is to run and maintain Netragard’s Exploit Acquisition Program (EAP). EAP is designed to acquire bleeding edge, high value research and intelligence from the hacking community.&lt;br /&gt;
&lt;br /&gt;
=== Brian Weekes ===&lt;br /&gt;
'''GMO'''&amp;lt;br/&amp;gt;&lt;br /&gt;
''Panelist'' &amp;lt;br/&amp;gt;&lt;br /&gt;
Brian Weekes is an Infrastructure Team Lead at GMO managing the Linux Engineering group with over 14 years of experience in Information Technology.  He played a major role in developing the foundation for the market data plant and trading platforms used for quantitative trading and research.  Prior to joining GMO, Brian worked at Wyeth as a Senior Systems Architect to build a new infrastructure and migrate scientific discovery research to high performance computing environments on the Linux platform. &lt;br /&gt;
&lt;br /&gt;
{{2010 BASC:Section Template | Conference Organizers}}&lt;br /&gt;
* Conference Organizer&lt;br /&gt;
** [mailto:jim.weiler@owasp.org Jim Weiler], Chairperson&lt;br /&gt;
* Program Committee: &lt;br /&gt;
** [mailto:mark.arnold@something.somewhere.com Mark Arnold]&lt;br /&gt;
** [mailto:zach.lanier@something.somewhere.com Zach Lanier]&lt;br /&gt;
** [mailto:jim.weiler@owasp.org Jim Weiler], Chairperson&lt;br /&gt;
* Sponsorship Committee: &lt;br /&gt;
** [mailto:mark.arnold@something.somewhere.com Mark Arnold]&lt;br /&gt;
* Website Editor &lt;br /&gt;
** [mailto:neil.smithline@owasp.org Neil Smithline]&lt;br /&gt;
&lt;br /&gt;
{{2010_BASC:Footer_Template | Speakers}}&lt;/div&gt;</summary>
		<author><name>Mark A. Arnold</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=2010_BASC_Sponsors&amp;diff=93351</id>
		<title>2010 BASC Sponsors</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=2010_BASC_Sponsors&amp;diff=93351"/>
				<updated>2010-11-19T20:42:51Z</updated>
		
		<summary type="html">&lt;p&gt;Mark A. Arnold: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;&amp;lt;div style=&amp;quot;font-size:110%; font-weight:bold;&amp;quot;&amp;gt;&lt;br /&gt;
We kindly thank our [[2010 BASC Sponsors|sponsors]] for their support. Please help us keep future BASCs free by visiting our sponsors.&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;/div&amp;gt;&amp;lt;/center&amp;gt;&lt;br /&gt;
== Platinum Sponsors (Listed Alphabetically) ==&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
[[File:Core_Logo_Final_Word_3_10.png|link=http://www.coresecurity.com//|CORE Security]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:150%&amp;quot;&amp;gt;Visit [http://www.coresecurity.com CORE Security]&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
[[File:Rapid7LogoLarge.png|alt=Rapid7|link=http://Rapid7.com|Rapid7]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:150%&amp;quot;&amp;gt;Visit [http://rapid7.com Rapid7]&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
[[File:Safelight_logo_large.gif|alt=SafeLight Logo|link=http://safelightsecurity.com|SafeLight Security Advisors]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:150%&amp;quot;&amp;gt;Visit [http://safelightsecurity.com SafeLight Security Advisors].&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
[[File:SI-Banner-755x160-v2.jpg|alt=Security Innovation Logo|link=http://securityinnovation.com|Security Innovation]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:150%&amp;quot;&amp;gt;Visit [http://securityinnovation.com Security Innovation].&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
[[File:boston-2010-source-500x126.jpg|link=http://www.sourceconference.com/|SOURCE]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:150%&amp;quot;&amp;gt;Visit [http://www.sourceconference.com/ SOURCE].&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;/center&amp;gt;&lt;br /&gt;
== Gold Sponsors (Listed Alphabetically) ==&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
[[File:AuricLogo_300x133.png|link=http://www.auricsystems.com|Auric Systems International]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:150%&amp;quot;&amp;gt;Visit [http://www.auricsystems.com Auric Systems International]&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
[[File:PAN-TNSC-290x109.jpg|link=http://www.paloaltonetworks.com/|Palo Alto Networks]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:150%&amp;quot;&amp;gt;Visit [http://www.paloaltonetworks.com/ Palo Alto Networks]&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
[[File:Whitehatlogo-medium.png|link=http://www.whitehatsec.com|WhiteHat Security]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:150%&amp;quot;&amp;gt;Visit [http://whitehatsec.com WhiteHat Security]&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
[[File:AppSecDC-2010-Sponsor-fortifyhp.gif|link=https://www.fortify.com/|Fortify]]&lt;br /&gt;
&amp;lt;/center&amp;gt;&lt;br /&gt;
{{2010_BASC:Footer_Template | Sponsors}}&lt;/div&gt;</summary>
		<author><name>Mark A. Arnold</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=2010_BASC_Speakers&amp;diff=93290</id>
		<title>2010 BASC Speakers</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=2010_BASC_Speakers&amp;diff=93290"/>
				<updated>2010-11-18T22:08:35Z</updated>
		
		<summary type="html">&lt;p&gt;Mark A. Arnold: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{2010_BASC:Header_Template | Speakers}}&lt;br /&gt;
__FORCETOC__&lt;br /&gt;
We would like to thank our speakers for donating their time and effort to help make this conference successful.&lt;br /&gt;
&lt;br /&gt;
=== Josh Corman === &lt;br /&gt;
'''The 451 Group'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Joshua Corman is the Research Director of the 451 Group's enterprise security practice. Corman has more than a decade of experience with security and networking software, most recently serving as Principal Security Strategist for IBM Internet Security Systems. Corman’s research cuts across sectors to the core challenges of the industry, and drives evolutionary strategies toward emerging technologies and shifting economics. Corman is a candid and highly coveted speaker and has spoken at leading industry events such as RSA, Interop, ISACA, and SANS. His efforts to educate and challenge the industry recently lead NetworkWorld magazine to recognize him as a [http://www.networkworld.com/supp/2009/outlook/010509-tech-people-to-know.html top innovators of IT] for 2009. Corman also serves on the Faculty for IANS and is a staunch advocate for CISOs everywhere. In 2010, Corman also co-founded [http://rugedsoftware.org RuggedSoftware.org] – a value based initiative to raise awareness and usher in an era of secure digital infrastructure.&lt;br /&gt;
&lt;br /&gt;
=== Ming Chow ===&lt;br /&gt;
'''Tufts University, CS Department'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Ming Chow is a scholar of science and technology and a Lecturer at the Tufts University Department of Computer Science.  His areas of interests are computer security, game development, web application security, and Computer Science in Education. Ming co-edited a special issue of IEEE Security &amp;amp; Privacy on securing online games with Gary McGraw of Cigital, Inc. published in May 2009. Ming is a frequent guest speaker, and have spoke at numerous organizations, including New England Association of Insurance Fraud Investigators (NEAIFI), and the New England Chapter of the High Technology Crime Investigation Association (HTCIA-NE), the Greater Boston Chapter of the Association of Certified Fraud Examiners (ACFE), John Hancock, and the Massachusetts Office of the Attorney General (AGO). Finally, Ming is a SANS GIAC Certified Incident Handler (GCIH).&lt;br /&gt;
&lt;br /&gt;
=== Andrew Gronosky  ===&lt;br /&gt;
'''Raytheon/BBN Technologies'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Mr. Andrew Gronosky is a staff engineer at Raytheon BBN Technologies. He has experience developing software for a variety of applications including data analysis and visualization, digital signal processing, and parallel and distributed systems. He holds a Master of Science degree in mathematics from Rensselaer Polytechnic Institute and is a member of the IEEE and the ACM. &amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Joshua &amp;quot;Jabra&amp;quot; Abraham, Will Vandevanter  ===&lt;br /&gt;
'''Rapid7'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Joshua &amp;quot;Jabra&amp;quot; Abraham joined Rapid7 in 2006 as a Security Consultant. Josh has extensive IT Security and Auditing experience and worked as an enterprise risk assessment analyst for Hasbro Corporation. Josh specializes in penetration testing, web application security assessments, wireless security assessments, and custom code development. He has spoken at BlackHat, DefCon, ShmooCon, The SANS Pentest Summit, Infosec World, CSI, OWASP Conferences, LinuxWorld, Comdex and BLUG. In his spare time, he contributes code to open source security projects such as the BackTrack LiveCD, BeEF, Nikto, Fierce, and PBNJ. He is frequently quoted in the media regarding Microsoft Patch Tuesday and web application security by ComputerWorld, DarkReading and SC Magazine.&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
Mr. Vandevanter joined Rapid7 in 2008. Will has IT Security experience with a focus in web application security and secure software engineering. Will specializes in penetration testing, web application security assessments, and secure code development. In the past Will has also worked on a few different Open Source security projects including porting SELinux to OpenMoko and other Linux based mobile platforms. Will holds a Bachelors Degree in Mathematics and Computer Science from McGill University and Masters Degree in Computer Science from James Madison University.&lt;br /&gt;
&lt;br /&gt;
=== Christien Rioux  ===&lt;br /&gt;
'''SOURCE Conference/Veracode'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Christien Rioux is co-founder and chief scientist of Veracode, the world's only binary-analysis powered online application risk management service. Prior to Veracode, he was a founder at security consulting firm @stake, a member of the hacker think-tank L0pht Heavy Industries, and a graduate of Massachusetts Institute Of Technology.&lt;br /&gt;
Today, he focuses on algorithms to automate the difficult task of reverse-engineering and analyzing binaries for security vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
=== Paul Schofield  ===&lt;br /&gt;
'''Imperva'''&amp;lt;br/&amp;gt;&lt;br /&gt;
With broad business and technical experience ranging from mergers and acquisitions to incident response and investigations, Paul Schofield is a frequent and energetic public speaker.&lt;br /&gt;
With over fourteen years of experience in Information Security and Risk Management, his diverse background he brings insightful perspectives to security and risk management discussions.&lt;br /&gt;
Paul is currently a Senior Security Engineer with Imperva,  an award winning application Security company.&lt;br /&gt;
&lt;br /&gt;
=== Rob Cheyne  ===&lt;br /&gt;
'''Safelight Security Advisors'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Rob was one of a select few at security consulting company @stake who regularly led and conducted full-blown enterprise-level architecture assessments for Fortune 500 companies.  Drawing from his experience with dozens of real-world architecture assessments over the past 12 years, and his 20 years as a software developer, architect, and consultant, Rob teaches students to challenge assumptions that frequently lead to long-term security and reliability problems. &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== John Carmichael  ===&lt;br /&gt;
'''Safelight Security Advisors'''&amp;lt;br/&amp;gt;&lt;br /&gt;
John Carmichael applies his software security expertise to the creation and delivery of world class security training for some of the world’s largest organizations.  At Safelight Security Advisors, he is an integral part of the product team creating best of breed computer-based training courses. Prior to joining Safelight Security Advisors, John was a security trainer and consultant at both Security Innovation and Cigital.  His software security experience is rooted in a background of software development with deep expertise in a myriad of languages and environments.  He has developed enterprise class software for large organizations such as Massachusetts Executive Office of Health and Human Services and Computer Science Corporation. John earned his B.S. degree in Computer Science and Business Administration from the University of Vermont and an M.S. degree in Computer Information System Security from Boston University.&lt;br /&gt;
&lt;br /&gt;
=== Dan Crowley ===&lt;br /&gt;
'''Core Security'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Dan Crowley is an independent security researcher and lecturer also working for Core Security Technologies. Dan runs a security education group called CSEC, which is in the process of becoming a hackerspace. In his free time, he can frequently be found playing with Web-based technologies and locks.&lt;br /&gt;
=== Kenneth Smith ===&lt;br /&gt;
Ken Smith, CISSP, CISA, GCIH is an Enterprise Information Security Architect with 15 years of experience in the information security space.  He currently leads efforts related to IT risk management, compliance, and privacy for a private $1B e-Commerce, Catalog, and Retail organization.  As a consultant, and former QSA, Ken has an extensive background in PCI DSS and has helped many organizations in the area of strategic planning, assessment, remediation plan development, and security program design. &amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Zach Lanier ===&lt;br /&gt;
'''Intrepidus Group'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Zach Lanier is a Senior Security Consultant with the Intrepidus Group, a firm specializing in security assessment services. Zach's areas of focus&lt;br /&gt;
are network and application penetration testing, intrusion analysis, and general hackery, with frequent dabbling in security and privacy research.&lt;br /&gt;
&lt;br /&gt;
=== Shakeel Tufail  ===&lt;br /&gt;
'''Fortify'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Shakeel Tufail is a Federal Practice Manager at Fortify, an HP company, where his responsibilities include refining customer security requirements, managing Fortify product deployments and delivering security services.&lt;br /&gt;
Mr. Tufail brings over 18 years of experience to the IT industry in the areas of network engineering, software development, quality assurance, risk management, and security.&lt;br /&gt;
Recently, he led over 30 enterprise security assessments for DoD and Fortune Top 50 commercial organizations that directly led to improvement of their risk profile.&lt;br /&gt;
Prior to joining Fortify, Mr. Tufail held positions such as Deputy Program Manager for the Pentagon Force Protection Agency, Managing Partner for Insyte, General Manager of CompUSA, and Lead Release Engineer for AOL Time-Warner’s AOL Instant Messenger development team and HOST Servers QA group.&lt;br /&gt;
An active software assurance community member, Mr. Tufail contributes to standards-defining efforts including the Common Weakness Enumeration (CWE), the Common Attack Pattern Enumeration and Classification (CAPEC) and other elements of the Software Assurance Programs of the Department of Homeland Security, NSA, and the Department of Defense. He has accumulated over 25 industry standard certifications and is a member of OWASP, ISACA, ISSA, and IEEE. In his spare time, Shakeel enjoys travel, photography, and technical training at local schools. Recently, he hiked the Himalayas to Mt. Everest basecamp.&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{{2010 BASC:Section Template | Conference Organizers}}&lt;br /&gt;
* Conference Organizer&lt;br /&gt;
** [mailto:jim.weiler@owasp.org Jim Weiler], Chairperson&lt;br /&gt;
* Program Committee: &lt;br /&gt;
** [mailto:mark.arnold@something.somewhere.com Mark Arnold]&lt;br /&gt;
** [mailto:zach.lanier@something.somewhere.com Zach Lanier]&lt;br /&gt;
** [mailto:jim.weiler@owasp.org Jim Weiler], Chairperson&lt;br /&gt;
* Sponsorship Committee: &lt;br /&gt;
** [mailto:mark.arnold@something.somewhere.com Mark Arnold]&lt;br /&gt;
* Website Editor &lt;br /&gt;
** [mailto:neil.smithline@owasp.org Neil Smithline]&lt;br /&gt;
&lt;br /&gt;
{{2010_BASC:Footer_Template | Speakers}}&lt;/div&gt;</summary>
		<author><name>Mark A. Arnold</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=2010_BASC_Speakers&amp;diff=93289</id>
		<title>2010 BASC Speakers</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=2010_BASC_Speakers&amp;diff=93289"/>
				<updated>2010-11-18T22:07:21Z</updated>
		
		<summary type="html">&lt;p&gt;Mark A. Arnold: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{2010_BASC:Header_Template | Speakers}}&lt;br /&gt;
__FORCETOC__&lt;br /&gt;
We would like to thank our speakers for donating their time and effort to help make this conference successful.&lt;br /&gt;
&lt;br /&gt;
=== Josh Corman === &lt;br /&gt;
'''The 451 Group'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Joshua Corman is the Research Director of the 451 Group's enterprise security practice. Corman has more than a decade of experience with security and networking software, most recently serving as Principal Security Strategist for IBM Internet Security Systems. Corman’s research cuts across sectors to the core challenges of the industry, and drives evolutionary strategies toward emerging technologies and shifting economics. Corman is a candid and highly coveted speaker and has spoken at leading industry events such as RSA, Interop, ISACA, and SANS. His efforts to educate and challenge the industry recently lead NetworkWorld magazine to recognize him as a [http://www.networkworld.com/supp/2009/outlook/010509-tech-people-to-know.html top innovators of IT] for 2009. Corman also serves on the Faculty for IANS and is a staunch advocate for CISOs everywhere. In 2010, Corman also co-founded [http://rugedsoftware.org RuggedSoftware.org] – a value based initiative to raise awareness and usher in an era of secure digital infrastructure.&lt;br /&gt;
&lt;br /&gt;
=== Ming Chow ===&lt;br /&gt;
'''Tufts University, CS Department'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Ming Chow is a scholar of science and technology and a Lecturer at the Tufts University Department of Computer Science.  His areas of interests are computer security, game development, web application security, and Computer Science in Education. Ming co-edited a special issue of IEEE Security &amp;amp; Privacy on securing online games with Gary McGraw of Cigital, Inc. published in May 2009. Ming is a frequent guest speaker, and have spoke at numerous organizations, including New England Association of Insurance Fraud Investigators (NEAIFI), and the New England Chapter of the High Technology Crime Investigation Association (HTCIA-NE), the Greater Boston Chapter of the Association of Certified Fraud Examiners (ACFE), John Hancock, and the Massachusetts Office of the Attorney General (AGO). Finally, Ming is a SANS GIAC Certified Incident Handler (GCIH).&lt;br /&gt;
&lt;br /&gt;
=== Andrew Gronosky  ===&lt;br /&gt;
'''Raytheon/BBN Technologies'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Mr. Andrew Gronosky is a staff engineer at Raytheon BBN Technologies. He has experience developing software for a variety of applications including data analysis and visualization, digital signal processing, and parallel and distributed systems. He holds a Master of Science degree in mathematics from Rensselaer Polytechnic Institute and is a member of the IEEE and the ACM. &amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Joshua &amp;quot;Jabra&amp;quot; Abraham, Will Vandevanter  ===&lt;br /&gt;
'''Rapid7'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Joshua &amp;quot;Jabra&amp;quot; Abraham joined Rapid7 in 2006 as a Security Consultant. Josh has extensive IT Security and Auditing experience and worked as an enterprise risk assessment analyst for Hasbro Corporation. Josh specializes in penetration testing, web application security assessments, wireless security assessments, and custom code development. He has spoken at BlackHat, DefCon, ShmooCon, The SANS Pentest Summit, Infosec World, CSI, OWASP Conferences, LinuxWorld, Comdex and BLUG. In his spare time, he contributes code to open source security projects such as the BackTrack LiveCD, BeEF, Nikto, Fierce, and PBNJ. He is frequently quoted in the media regarding Microsoft Patch Tuesday and web application security by ComputerWorld, DarkReading and SC Magazine.&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
Mr. Vandevanter joined Rapid7 in 2008. Will has IT Security experience with a focus in web application security and secure software engineering. Will specializes in penetration testing, web application security assessments, and secure code development. In the past Will has also worked on a few different Open Source security projects including porting SELinux to OpenMoko and other Linux based mobile platforms. Will holds a Bachelors Degree in Mathematics and Computer Science from McGill University and Masters Degree in Computer Science from James Madison University.&lt;br /&gt;
&lt;br /&gt;
=== Christien Rioux  ===&lt;br /&gt;
'''SOURCE Conference/Veracode'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Christien Rioux is co-founder and chief scientist of Veracode, the world's only binary-analysis powered online application risk management service. Prior to Veracode, he was a founder at security consulting firm @stake, a member of the hacker think-tank L0pht Heavy Industries, and a graduate of Massachusetts Institute Of Technology.&lt;br /&gt;
Today, he focuses on algorithms to automate the difficult task of reverse-engineering and analyzing binaries for security vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
=== Paul Schofield  ===&lt;br /&gt;
'''Imperva'''&amp;lt;br/&amp;gt;&lt;br /&gt;
With broad business and technical experience ranging from mergers and acquisitions to incident response and investigations, Paul Schofield is a frequent and energetic public speaker.&lt;br /&gt;
With over fourteen years of experience in Information Security and Risk Management, his diverse background he brings insightful perspectives to security and risk management discussions.&lt;br /&gt;
Paul is currently a Senior Security Engineer with Imperva,  an award winning application Security company.&lt;br /&gt;
&lt;br /&gt;
=== Rob Cheyne  ===&lt;br /&gt;
'''Safelight Security Advisors'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Rob was one of a select few at security consulting company @stake who regularly led and conducted full-blown enterprise-level architecture assessments for Fortune 500 companies.  Drawing from his experience with dozens of real-world architecture assessments over the past 12 years, and his 20 years as a software developer, architect, and consultant, Rob teaches students to challenge assumptions that frequently lead to long-term security and reliability problems. &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== John Carmichael  ===&lt;br /&gt;
'''Safelight Security Advisors'''&amp;lt;br/&amp;gt;&lt;br /&gt;
John Carmichael applies his software security expertise to the creation and delivery of world class security training for some of the world’s largest organizations.  At Safelight Security Advisors, he is an integral part of the product team creating best of breed computer-based training courses. Prior to joining Safelight Security Advisors, John was a security trainer and consultant at both Security Innovation and Cigital.  His software security experience is rooted in a background of software development with deep expertise in a myriad of languages and environments.  He has developed enterprise class software for large organizations such as Massachusetts Executive Office of Health and Human Services and Computer Science Corporation. John earned his B.S. degree in Computer Science and Business Administration from the University of Vermont and an M.S. degree in Computer Information System Security from Boston University.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Dan Crowley ===&lt;br /&gt;
'''Core Security'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Dan Crowley is an independent security researcher and lecturer also working for Core Security Technologies. Dan runs a security education group called CSEC, which is in the process of becoming a hackerspace. In his free time, he can frequently be found playing with Web-based technologies and locks.&lt;br /&gt;
=== Kenneth Smith ===&lt;br /&gt;
Ken Smith, CISSP, CISA, GCIH is an Enterprise Information Security Architect with 15 years of experience in the information security space.  He currently leads efforts related to IT risk management, compliance, and privacy for a private $1B e-Commerce, Catalog, and Retail organization.  As a consultant, and former QSA, Ken has an extensive background in PCI DSS and has helped many organizations in the area of strategic planning, assessment, remediation plan development, and security program design. &amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Zach Lanier ===&lt;br /&gt;
'''Intrepidus Group'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Zach Lanier is a Senior Security Consultant with the Intrepidus Group, a firm specializing in security assessment services. Zach's areas of focus&lt;br /&gt;
are network and application penetration testing, intrusion analysis, and general hackery, with frequent dabbling in security and privacy research.&lt;br /&gt;
&lt;br /&gt;
=== Shakeel Tufail  ===&lt;br /&gt;
'''Fortify'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Shakeel Tufail is a Federal Practice Manager at Fortify, an HP company, where his responsibilities include refining customer security requirements, managing Fortify product deployments and delivering security services.&lt;br /&gt;
Mr. Tufail brings over 18 years of experience to the IT industry in the areas of network engineering, software development, quality assurance, risk management, and security.&lt;br /&gt;
Recently, he led over 30 enterprise security assessments for DoD and Fortune Top 50 commercial organizations that directly led to improvement of their risk profile.&lt;br /&gt;
Prior to joining Fortify, Mr. Tufail held positions such as Deputy Program Manager for the Pentagon Force Protection Agency, Managing Partner for Insyte, General Manager of CompUSA, and Lead Release Engineer for AOL Time-Warner’s AOL Instant Messenger development team and HOST Servers QA group.&lt;br /&gt;
An active software assurance community member, Mr. Tufail contributes to standards-defining efforts including the Common Weakness Enumeration (CWE), the Common Attack Pattern Enumeration and Classification (CAPEC) and other elements of the Software Assurance Programs of the Department of Homeland Security, NSA, and the Department of Defense. He has accumulated over 25 industry standard certifications and is a member of OWASP, ISACA, ISSA, and IEEE. In his spare time, Shakeel enjoys travel, photography, and technical training at local schools. Recently, he hiked the Himalayas to Mt. Everest basecamp.&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{{2010 BASC:Section Template | Conference Organizers}}&lt;br /&gt;
* Conference Organizer&lt;br /&gt;
** [mailto:jim.weiler@owasp.org Jim Weiler], Chairperson&lt;br /&gt;
* Program Committee: &lt;br /&gt;
** [mailto:mark.arnold@something.somewhere.com Mark Arnold]&lt;br /&gt;
** [mailto:zach.lanier@something.somewhere.com Zach Lanier]&lt;br /&gt;
** [mailto:jim.weiler@owasp.org Jim Weiler], Chairperson&lt;br /&gt;
* Sponsorship Committee: &lt;br /&gt;
** [mailto:mark.arnold@something.somewhere.com Mark Arnold]&lt;br /&gt;
* Website Editor &lt;br /&gt;
** [mailto:neil.smithline@owasp.org Neil Smithline]&lt;br /&gt;
&lt;br /&gt;
{{2010_BASC:Footer_Template | Speakers}}&lt;/div&gt;</summary>
		<author><name>Mark A. Arnold</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=2010_BASC_Presentations&amp;diff=93288</id>
		<title>2010 BASC Presentations</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=2010_BASC_Presentations&amp;diff=93288"/>
				<updated>2010-11-18T22:02:46Z</updated>
		
		<summary type="html">&lt;p&gt;Mark A. Arnold: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{2010_BASC:Header_Template | Presentations}}&lt;br /&gt;
__FORCETOC__&lt;br /&gt;
We would like to thank our speakers for donating their time and effort to help make this conference successful.&lt;br /&gt;
{{2010_BASC:Presentaton_Info_Template|HTML5 Security|Ming Chow|10|10|1}}&lt;br /&gt;
The power of HTML5 allows developers to create &lt;br /&gt;
web applications not just structured content, but its new features has increased the attack surface.  This presentation will demo and discuss new attack opportunities, particularly on client machines, including abusing the offline application cache and SQL injection via file-based client-side databases.&lt;br /&gt;
{{2010_BASC:Presentaton_Info_Template|A Crumple Zone for Service Oriented Architectures|Andrew Gronosky|11|11|1}}&lt;br /&gt;
We present a new architectural construct analogous to the crumple zone in an automobile.  It consists of a layer of intelligent service proxies that work together to provide both signature-based and non-signature based defenses. We present our initial design for Java RMI based services and compare it with  web application firewalls.&lt;br /&gt;
{{2010_BASC:Presentaton_Info_Template|Hacking SAP BusinessObjects|Joshua Abraham and Will Vandevanter|13|13|1}}&lt;br /&gt;
Business intelligence is a multi-billion industry. At the top of the product food chain is BusinessObjects. BusinessObjects is a very widely deployed business intelligence tool that’s focus is in managing, querying, analyzing, and reporting on business data. It is used by government entities (e.g. U.S Air Force), telecom companies (e.g. Verizon), car manufacturers (e.g. Nissan), and beverage companies (e.g. Coors) to retain and control vast amounts of data. If you are a penetration tester chances are you have run into at least one BusinessObjects server during an engagement. Yet, very few vulnerabilities have been publically released and, to the best of the authors knowledge, no white papers have been released on attack methodologies for BusinessObjects itself. In this presentation we will present the entire lifecycle of attacking a BusinessObjects server from external and internal enumeration (e.g. Google dorks), fingerprinting techniques, account enumeration vulnerabilities, specific attack vectors for gaining access to accounts, privilege escalation vulnerabilities, and eventually full system compromise vulnerabilities that we have found during our research. Anyone interesting in attacking an organization that has BusinessObjects or SOA deployed in their environment should attend this talk.&lt;br /&gt;
{{2010_BASC:Presentaton_Info_Template|What's Old Is New Again: An Overview of Mobile Application Security|Zach Lanier|14|14|1}}&lt;br /&gt;
The ever-increasing prevalence of mobile devices brings with it a slew of security problems. Applications running directly on mobile devices(and web apps optimized for mobile clients) are ripe for the picking even by unsophisticated attackers. The attack classes that once applied to traditional network-facing, fat client, and web applications are now&lt;br /&gt;
valid for mobile apps, as well. Insecure authentication and access control; home-grown crypto; and memory management problems are just some of the issues resurfacing on this new frontier. This presentation will discuss the security of some of the most popular applications running on mainstream mobile platforms such as Android, iPhone, Blackberry, and Windows Mobile.&lt;br /&gt;
{{2010_BASC:Presentaton_Info_Template|Business Logic Attacks - BATs and BLBs|Paul Schofield|15|15|1}}&lt;br /&gt;
Business logic attacks are a set of legal application transactions that are used to carry out a malicious operation that is not part of normal business practices. This presentation will provide a quick introduction to business logic attacks, their unique characteristics and the motivation behind their uptick. . Concluding this session we will discuss using multiple advanced techniques to battle these attacks, rather than relying exclusively on application code&lt;br /&gt;
{{2010_BASC:Presentaton_Info_Template|The Exploit Arms Race|Christien Rioux|16|16|1}}&lt;br /&gt;
As defenses to exploits have become more sophisticated, so have the attacks required to circumvent them. A historical perspective will be presented, elaborating on the techniques used and the real reason why they were developed. Modern exploit technique has its roots in solving problems for the attacker, resulting in advanced exploits for the following&lt;br /&gt;
categories of flaw: Stack Overflows, Heap Overflows, Cross-Site Scripting, SQL Injection, and Path Manipulations. Learn about the roots of techniques like Stack cookies/Stackguard/Run-Time Stack Checking, DEP and ASLR, from attacks like trampolining, return-oriented programming, the evolution of fuzzing techniques, static and dynamic analysis for both attacking software.&lt;br /&gt;
{{2010_BASC:Presentaton_Info_Template|OWASP Basics 1 and 2|Robert Cheyne|10|11|2}}&lt;br /&gt;
Rob presents a number of scenarios that walk participants through the basics of SQL injection, XSS and CSRF, along with a few other tricks he has up his sleeve.  Participants will come away with a foundation for further security learning.  Those already knowledgeable on application security issues will learn some new techniques for presenting and teaching this information in a clear, concise and effective manner.&lt;br /&gt;
{{2010_BASC:Presentaton_Info_Template|Coffee Shop Warefare:Protecting Yourself in Dark Territory|To Be Determined|13|13|2}}&lt;br /&gt;
A lighthearted look at the real threats that people face in personal computing, specifically when connected to unknown network at coffee shops and airports. John will cover many of these threats and discuss tools and best practices everyone can engage in to ensure they protect their machine and information from these risks.&lt;br /&gt;
{{2010_BASC:Presentaton_Info_Template|Url Enlargement|Dan Crowley|14|14|2}}&lt;br /&gt;
URL shorteners are ubiquitous in today's Internet culture and have a variety of uses for a variety of users. While many have theorized about the security issues and usages involved with URL shortening services (of which there are an impressive number), this talk will aim to demonstrate them, along with interesting statistics such as the percentage of Goatse-equivalent short URLs. Come see what's behind the short URLs: personal documents, parasitic storage, authentication credentials, attacks and more!&lt;br /&gt;
{{2010_BASC:Presentaton_Info_Template|Web Applications and Data Tokenization|Kenny Smith|15|15|2}}&lt;br /&gt;
Tokenization has become increasingly popular as a method to protect sensitive data and reduce the scope of security requirements such as PCI DSS.  Many solutions now integrate directly with web applications, tokenizing data before it ever reaches internal corporate systems.  As developers, you may be tasked with integrating tokenization into your applications.  If done correctly, this can be a big win for your organization.  This talk will cover the types of tokenization solutions, seeing through the marketing hype and vendor claims, and how to avoid some common mistakes that could greatly reduce tokenizations effectiveness.   &lt;br /&gt;
{{2010_BASC:Presentaton_Info_Template|Open SAMM|Shakeel Tufail|16|16|2}}&lt;br /&gt;
SAMM is an open framework to help organizations formulate and implement a strategy for software security that is tailored to the specific risks facing the organization. The building blocks of the model are the three maturity levels defined for each of the twelve security practices. These define a wide variety of activities to reduce security risks and increase software assurance. Additional details are included to measure successful activity performance, understand the associated assurance benefits, estimate personnel and other costs.&lt;br /&gt;
{{2010_BASC:Footer_Template | Presentations}}&lt;/div&gt;</summary>
		<author><name>Mark A. Arnold</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=2010_BASC_Speakers&amp;diff=93287</id>
		<title>2010 BASC Speakers</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=2010_BASC_Speakers&amp;diff=93287"/>
				<updated>2010-11-18T21:57:42Z</updated>
		
		<summary type="html">&lt;p&gt;Mark A. Arnold: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{2010_BASC:Header_Template | Speakers}}&lt;br /&gt;
__FORCETOC__&lt;br /&gt;
We would like to thank our speakers for donating their time and effort to help make this conference successful.&lt;br /&gt;
&lt;br /&gt;
=== Josh Corman === &lt;br /&gt;
'''The 451 Group'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Joshua Corman is the Research Director of the 451 Group's enterprise security practice. Corman has more than a decade of experience with security and networking software, most recently serving as Principal Security Strategist for IBM Internet Security Systems. Corman’s research cuts across sectors to the core challenges of the industry, and drives evolutionary strategies toward emerging technologies and shifting economics. Corman is a candid and highly coveted speaker and has spoken at leading industry events such as RSA, Interop, ISACA, and SANS. His efforts to educate and challenge the industry recently lead NetworkWorld magazine to recognize him as a [http://www.networkworld.com/supp/2009/outlook/010509-tech-people-to-know.html top innovators of IT] for 2009. Corman also serves on the Faculty for IANS and is a staunch advocate for CISOs everywhere. In 2010, Corman also co-founded [http://rugedsoftware.org RuggedSoftware.org] – a value based initiative to raise awareness and usher in an era of secure digital infrastructure.&lt;br /&gt;
&lt;br /&gt;
=== Ming Chow ===&lt;br /&gt;
'''Tufts University, CS Department'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Ming Chow is a scholar of science and technology and a Lecturer at the Tufts University Department of Computer Science.  His areas of interests are computer security, game development, web application security, and Computer Science in Education. Ming co-edited a special issue of IEEE Security &amp;amp; Privacy on securing online games with Gary McGraw of Cigital, Inc. published in May 2009. Ming is a frequent guest speaker, and have spoke at numerous organizations, including New England Association of Insurance Fraud Investigators (NEAIFI), and the New England Chapter of the High Technology Crime Investigation Association (HTCIA-NE), the Greater Boston Chapter of the Association of Certified Fraud Examiners (ACFE), John Hancock, and the Massachusetts Office of the Attorney General (AGO). Finally, Ming is a SANS GIAC Certified Incident Handler (GCIH).&lt;br /&gt;
&lt;br /&gt;
=== Andrew Gronosky  ===&lt;br /&gt;
'''Raytheon/BBN Technologies'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Mr. Andrew Gronosky is a staff engineer at Raytheon BBN Technologies. He has experience developing software for a variety of applications including data analysis and visualization, digital signal processing, and parallel and distributed systems. He holds a Master of Science degree in mathematics from Rensselaer Polytechnic Institute and is a member of the IEEE and the ACM. &amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Joshua &amp;quot;Jabra&amp;quot; Abraham, Will Vandevanter  ===&lt;br /&gt;
'''Rapid7'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Joshua &amp;quot;Jabra&amp;quot; Abraham joined Rapid7 in 2006 as a Security Consultant. Josh has extensive IT Security and Auditing experience and worked as an enterprise risk assessment analyst for Hasbro Corporation. Josh specializes in penetration testing, web application security assessments, wireless security assessments, and custom code development. He has spoken at BlackHat, DefCon, ShmooCon, The SANS Pentest Summit, Infosec World, CSI, OWASP Conferences, LinuxWorld, Comdex and BLUG. In his spare time, he contributes code to open source security projects such as the BackTrack LiveCD, BeEF, Nikto, Fierce, and PBNJ. He is frequently quoted in the media regarding Microsoft Patch Tuesday and web application security by ComputerWorld, DarkReading and SC Magazine.&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
Mr. Vandevanter joined Rapid7 in 2008. Will has IT Security experience with a focus in web application security and secure software engineering. Will specializes in penetration testing, web application security assessments, and secure code development. In the past Will has also worked on a few different Open Source security projects including porting SELinux to OpenMoko and other Linux based mobile platforms. Will holds a Bachelors Degree in Mathematics and Computer Science from McGill University and Masters Degree in Computer Science from James Madison University.&lt;br /&gt;
&lt;br /&gt;
=== Christien Rioux  ===&lt;br /&gt;
'''SOURCE Conference/Veracode'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Christien Rioux is co-founder and chief scientist of Veracode, the world's only binary-analysis powered online application risk management service. Prior to Veracode, he was a founder at security consulting firm @stake, a member of the hacker think-tank L0pht Heavy Industries, and a graduate of Massachusetts Institute Of Technology.&lt;br /&gt;
Today, he focuses on algorithms to automate the difficult task of reverse-engineering and analyzing binaries for security vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
=== Paul Schofield  ===&lt;br /&gt;
'''Imperva'''&amp;lt;br/&amp;gt;&lt;br /&gt;
With broad business and technical experience ranging from mergers and acquisitions to incident response and investigations, Paul Schofield is a frequent and energetic public speaker.&lt;br /&gt;
With over fourteen years of experience in Information Security and Risk Management, his diverse background he brings insightful perspectives to security and risk management discussions.&lt;br /&gt;
Paul is currently a Senior Security Engineer with Imperva,  an award winning application Security company.&lt;br /&gt;
&lt;br /&gt;
=== Rob Cheyne  ===&lt;br /&gt;
'''Safelight Security Advisors'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Rob was one of a select few at security consulting company @stake who regularly led and conducted full-blown enterprise-level architecture assessments for Fortune 500 companies.  Drawing from his experience with dozens of real-world architecture assessments over the past 12 years, and his 20 years as a software developer, architect, and consultant, Rob teaches students to challenge assumptions that frequently lead to long-term security and reliability problems. &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== John Carmichael  ===&lt;br /&gt;
'''Safelight Security Advisors'''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Dan Crowley ===&lt;br /&gt;
'''Core Security'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Dan Crowley is an independent security researcher and lecturer also working for Core Security Technologies. Dan runs a security education group called CSEC, which is in the process of becoming a hackerspace. In his free time, he can frequently be found playing with Web-based technologies and locks.&lt;br /&gt;
=== Kenneth Smith ===&lt;br /&gt;
Ken Smith, CISSP, CISA, GCIH is an Enterprise Information Security Architect with 15 years of experience in the information security space.  He currently leads efforts related to IT risk management, compliance, and privacy for a private $1B e-Commerce, Catalog, and Retail organization.  As a consultant, and former QSA, Ken has an extensive background in PCI DSS and has helped many organizations in the area of strategic planning, assessment, remediation plan development, and security program design. &amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Zach Lanier ===&lt;br /&gt;
'''Intrepidus Group'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Zach Lanier is a Senior Security Consultant with the Intrepidus Group, a firm specializing in security assessment services. Zach's areas of focus&lt;br /&gt;
are network and application penetration testing, intrusion analysis, and general hackery, with frequent dabbling in security and privacy research.&lt;br /&gt;
&lt;br /&gt;
=== Shakeel Tufail  ===&lt;br /&gt;
'''Fortify'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Shakeel Tufail is a Federal Practice Manager at Fortify, an HP company, where his responsibilities include refining customer security requirements, managing Fortify product deployments and delivering security services.&lt;br /&gt;
Mr. Tufail brings over 18 years of experience to the IT industry in the areas of network engineering, software development, quality assurance, risk management, and security.&lt;br /&gt;
Recently, he led over 30 enterprise security assessments for DoD and Fortune Top 50 commercial organizations that directly led to improvement of their risk profile.&lt;br /&gt;
Prior to joining Fortify, Mr. Tufail held positions such as Deputy Program Manager for the Pentagon Force Protection Agency, Managing Partner for Insyte, General Manager of CompUSA, and Lead Release Engineer for AOL Time-Warner’s AOL Instant Messenger development team and HOST Servers QA group.&lt;br /&gt;
An active software assurance community member, Mr. Tufail contributes to standards-defining efforts including the Common Weakness Enumeration (CWE), the Common Attack Pattern Enumeration and Classification (CAPEC) and other elements of the Software Assurance Programs of the Department of Homeland Security, NSA, and the Department of Defense. He has accumulated over 25 industry standard certifications and is a member of OWASP, ISACA, ISSA, and IEEE. In his spare time, Shakeel enjoys travel, photography, and technical training at local schools. Recently, he hiked the Himalayas to Mt. Everest basecamp.&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{{2010 BASC:Section Template | Conference Organizers}}&lt;br /&gt;
* Conference Organizer&lt;br /&gt;
** [mailto:jim.weiler@owasp.org Jim Weiler], Chairperson&lt;br /&gt;
* Program Committee: &lt;br /&gt;
** [mailto:mark.arnold@something.somewhere.com Mark Arnold]&lt;br /&gt;
** [mailto:zach.lanier@something.somewhere.com Zach Lanier]&lt;br /&gt;
** [mailto:jim.weiler@owasp.org Jim Weiler], Chairperson&lt;br /&gt;
* Sponsorship Committee: &lt;br /&gt;
** [mailto:mark.arnold@something.somewhere.com Mark Arnold]&lt;br /&gt;
* Website Editor &lt;br /&gt;
** [mailto:neil.smithline@owasp.org Neil Smithline]&lt;br /&gt;
&lt;br /&gt;
{{2010_BASC:Footer_Template | Speakers}}&lt;/div&gt;</summary>
		<author><name>Mark A. Arnold</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=2010_BASC_Speakers&amp;diff=93286</id>
		<title>2010 BASC Speakers</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=2010_BASC_Speakers&amp;diff=93286"/>
				<updated>2010-11-18T21:57:04Z</updated>
		
		<summary type="html">&lt;p&gt;Mark A. Arnold: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{2010_BASC:Header_Template | Speakers}}&lt;br /&gt;
__FORCETOC__&lt;br /&gt;
We would like to thank our speakers for donating their time and effort to help make this conference successful and free.&lt;br /&gt;
&lt;br /&gt;
=== Josh Corman === &lt;br /&gt;
'''The 451 Group'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Joshua Corman is the Research Director of the 451 Group's enterprise security practice. Corman has more than a decade of experience with security and networking software, most recently serving as Principal Security Strategist for IBM Internet Security Systems. Corman’s research cuts across sectors to the core challenges of the industry, and drives evolutionary strategies toward emerging technologies and shifting economics. Corman is a candid and highly coveted speaker and has spoken at leading industry events such as RSA, Interop, ISACA, and SANS. His efforts to educate and challenge the industry recently lead NetworkWorld magazine to recognize him as a [http://www.networkworld.com/supp/2009/outlook/010509-tech-people-to-know.html top innovators of IT] for 2009. Corman also serves on the Faculty for IANS and is a staunch advocate for CISOs everywhere. In 2010, Corman also co-founded [http://rugedsoftware.org RuggedSoftware.org] – a value based initiative to raise awareness and usher in an era of secure digital infrastructure.&lt;br /&gt;
&lt;br /&gt;
=== Ming Chow ===&lt;br /&gt;
'''Tufts University, CS Department'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Ming Chow is a scholar of science and technology and a Lecturer at the Tufts University Department of Computer Science.  His areas of interests are computer security, game development, web application security, and Computer Science in Education. Ming co-edited a special issue of IEEE Security &amp;amp; Privacy on securing online games with Gary McGraw of Cigital, Inc. published in May 2009. Ming is a frequent guest speaker, and have spoke at numerous organizations, including New England Association of Insurance Fraud Investigators (NEAIFI), and the New England Chapter of the High Technology Crime Investigation Association (HTCIA-NE), the Greater Boston Chapter of the Association of Certified Fraud Examiners (ACFE), John Hancock, and the Massachusetts Office of the Attorney General (AGO). Finally, Ming is a SANS GIAC Certified Incident Handler (GCIH).&lt;br /&gt;
&lt;br /&gt;
=== Andrew Gronosky  ===&lt;br /&gt;
'''Raytheon/BBN Technologies'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Mr. Andrew Gronosky is a staff engineer at Raytheon BBN Technologies. He has experience developing software for a variety of applications including data analysis and visualization, digital signal processing, and parallel and distributed systems. He holds a Master of Science degree in mathematics from Rensselaer Polytechnic Institute and is a member of the IEEE and the ACM. &amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Joshua &amp;quot;Jabra&amp;quot; Abraham, Will Vandevanter  ===&lt;br /&gt;
'''Rapid7'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Joshua &amp;quot;Jabra&amp;quot; Abraham joined Rapid7 in 2006 as a Security Consultant. Josh has extensive IT Security and Auditing experience and worked as an enterprise risk assessment analyst for Hasbro Corporation. Josh specializes in penetration testing, web application security assessments, wireless security assessments, and custom code development. He has spoken at BlackHat, DefCon, ShmooCon, The SANS Pentest Summit, Infosec World, CSI, OWASP Conferences, LinuxWorld, Comdex and BLUG. In his spare time, he contributes code to open source security projects such as the BackTrack LiveCD, BeEF, Nikto, Fierce, and PBNJ. He is frequently quoted in the media regarding Microsoft Patch Tuesday and web application security by ComputerWorld, DarkReading and SC Magazine.&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
Mr. Vandevanter joined Rapid7 in 2008. Will has IT Security experience with a focus in web application security and secure software engineering. Will specializes in penetration testing, web application security assessments, and secure code development. In the past Will has also worked on a few different Open Source security projects including porting SELinux to OpenMoko and other Linux based mobile platforms. Will holds a Bachelors Degree in Mathematics and Computer Science from McGill University and Masters Degree in Computer Science from James Madison University.&lt;br /&gt;
&lt;br /&gt;
=== Christien Rioux  ===&lt;br /&gt;
'''SOURCE Conference/Veracode'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Christien Rioux is co-founder and chief scientist of Veracode, the world's only binary-analysis powered online application risk management service. Prior to Veracode, he was a founder at security consulting firm @stake, a member of the hacker think-tank L0pht Heavy Industries, and a graduate of Massachusetts Institute Of Technology.&lt;br /&gt;
Today, he focuses on algorithms to automate the difficult task of reverse-engineering and analyzing binaries for security vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
=== Paul Schofield  ===&lt;br /&gt;
'''Imperva'''&amp;lt;br/&amp;gt;&lt;br /&gt;
With broad business and technical experience ranging from mergers and acquisitions to incident response and investigations, Paul Schofield is a frequent and energetic public speaker.&lt;br /&gt;
With over fourteen years of experience in Information Security and Risk Management, his diverse background he brings insightful perspectives to security and risk management discussions.&lt;br /&gt;
Paul is currently a Senior Security Engineer with Imperva,  an award winning application Security company.&lt;br /&gt;
&lt;br /&gt;
=== Rob Cheyne  ===&lt;br /&gt;
'''Safelight Security Advisors'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Rob was one of a select few at security consulting company @stake who regularly led and conducted full-blown enterprise-level architecture assessments for Fortune 500 companies.  Drawing from his experience with dozens of real-world architecture assessments over the past 12 years, and his 20 years as a software developer, architect, and consultant, Rob teaches students to challenge assumptions that frequently lead to long-term security and reliability problems. &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== John Carmichael  ===&lt;br /&gt;
'''Safelight Security Advisors'''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Dan Crowley ===&lt;br /&gt;
'''Core Security'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Dan Crowley is an independent security researcher and lecturer also working for Core Security Technologies. Dan runs a security education group called CSEC, which is in the process of becoming a hackerspace. In his free time, he can frequently be found playing with Web-based technologies and locks.&lt;br /&gt;
=== Kenneth Smith ===&lt;br /&gt;
Ken Smith, CISSP, CISA, GCIH is an Enterprise Information Security Architect with 15 years of experience in the information security space.  He currently leads efforts related to IT risk management, compliance, and privacy for a private $1B e-Commerce, Catalog, and Retail organization.  As a consultant, and former QSA, Ken has an extensive background in PCI DSS and has helped many organizations in the area of strategic planning, assessment, remediation plan development, and security program design. &amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Zach Lanier ===&lt;br /&gt;
'''Intrepidus Group'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Zach Lanier is a Senior Security Consultant with the Intrepidus Group, a firm specializing in security assessment services. Zach's areas of focus&lt;br /&gt;
are network and application penetration testing, intrusion analysis, and general hackery, with frequent dabbling in security and privacy research.&lt;br /&gt;
&lt;br /&gt;
=== Shakeel Tufail  ===&lt;br /&gt;
'''Fortify'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Shakeel Tufail is a Federal Practice Manager at Fortify, an HP company, where his responsibilities include refining customer security requirements, managing Fortify product deployments and delivering security services.&lt;br /&gt;
Mr. Tufail brings over 18 years of experience to the IT industry in the areas of network engineering, software development, quality assurance, risk management, and security.&lt;br /&gt;
Recently, he led over 30 enterprise security assessments for DoD and Fortune Top 50 commercial organizations that directly led to improvement of their risk profile.&lt;br /&gt;
Prior to joining Fortify, Mr. Tufail held positions such as Deputy Program Manager for the Pentagon Force Protection Agency, Managing Partner for Insyte, General Manager of CompUSA, and Lead Release Engineer for AOL Time-Warner’s AOL Instant Messenger development team and HOST Servers QA group.&lt;br /&gt;
An active software assurance community member, Mr. Tufail contributes to standards-defining efforts including the Common Weakness Enumeration (CWE), the Common Attack Pattern Enumeration and Classification (CAPEC) and other elements of the Software Assurance Programs of the Department of Homeland Security, NSA, and the Department of Defense. He has accumulated over 25 industry standard certifications and is a member of OWASP, ISACA, ISSA, and IEEE. In his spare time, Shakeel enjoys travel, photography, and technical training at local schools. Recently, he hiked the Himalayas to Mt. Everest basecamp.&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{{2010 BASC:Section Template | Conference Organizers}}&lt;br /&gt;
* Conference Organizer&lt;br /&gt;
** [mailto:jim.weiler@owasp.org Jim Weiler], Chairperson&lt;br /&gt;
* Program Committee: &lt;br /&gt;
** [mailto:mark.arnold@something.somewhere.com Mark Arnold]&lt;br /&gt;
** [mailto:zach.lanier@something.somewhere.com Zach Lanier]&lt;br /&gt;
** [mailto:jim.weiler@owasp.org Jim Weiler], Chairperson&lt;br /&gt;
* Sponsorship Committee: &lt;br /&gt;
** [mailto:mark.arnold@something.somewhere.com Mark Arnold]&lt;br /&gt;
* Website Editor &lt;br /&gt;
** [mailto:neil.smithline@owasp.org Neil Smithline]&lt;br /&gt;
&lt;br /&gt;
{{2010_BASC:Footer_Template | Speakers}}&lt;/div&gt;</summary>
		<author><name>Mark A. Arnold</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=2010_BASC_Homepage&amp;diff=93285</id>
		<title>2010 BASC Homepage</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=2010_BASC_Homepage&amp;diff=93285"/>
				<updated>2010-11-18T21:20:26Z</updated>
		
		<summary type="html">&lt;p&gt;Mark A. Arnold: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[File:Boston-Banner-468x60.gif|right]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{{2010_BASC:Header_Template | Welcome}}&lt;br /&gt;
This is the homepage for the 2010 Boston Application Security Conference (BASC). This free conference will take place on Saturday, November 20&amp;lt;sup&amp;gt;th&amp;lt;/sup&amp;gt; at [http://microsoftcambridge.com/Default.aspx Microsoft New England Research and Development Center (NERD)].&lt;br /&gt;
&lt;br /&gt;
The BASC will be a free, one day, informal conference, aimed at increasing awareness and knowledge of application security in the greater Boston area. While many of the presentations will cover state-of-the-art application security concepts, the BASC is intended to appeal to a wide-array of attendees. Application security professionals, professional software developers, software quality engineers, computer science students, and security software vendors should be able to come to the BASC, learn, and hopefully enjoy themselves at the same time.&lt;br /&gt;
&lt;br /&gt;
{{2010 BASC:Section Template | The Details}}&lt;br /&gt;
* Date: Saturday, November 20&amp;lt;sup&amp;gt;th&amp;lt;/sup&amp;gt;, 2010&lt;br /&gt;
* Time: 8:00 AM - 7:00 PM&lt;br /&gt;
* Location: [http://microsoftcambridge.com/Default.aspx NERD]&lt;br /&gt;
* Directions: [http://microsoftcambridge.com/About/Directions/tabid/89/Default.aspx NERD's website] or [http://maps.google.com/places/us/ma/cambridge/memorial-dr/1/-microsoft-new-england-research-and-development-center?hl=en&amp;amp;gl=us Google Maps]&lt;br /&gt;
* Registration: [http://basc2010.eventbrite.com/ Online registration]&lt;br /&gt;
* Agenda: [[2010_BASC_Agenda | Agenda]]&lt;br /&gt;
* Speakers Details: [[2010_BASC_Speakers | Speakers]]&lt;br /&gt;
* Presentation Details: [[2010_BASC_Presentations | Presentations]]&lt;br /&gt;
* Call for papers: [[2010_BASC_Call_For_Papers | 2010 BASC CALL FOR PAPERS]]&lt;br /&gt;
&lt;br /&gt;
{{2010 BASC:Section Template | Registration}}&lt;br /&gt;
Admission to the BASC is free but registration is required for breakfast, lunch, and the evening social time. We will do everything possible to accommodate late registrants but the facility and food are limited. [http://basc2010.eventbrite.com/ Online registration] is now open and you are encouraged to register early.&lt;br /&gt;
&lt;br /&gt;
{{2010 BASC:Section Template | Call For Papers}}&lt;br /&gt;
We are accepting presentation proposals. If you are interested in being a presenter at the 2010 BASC, you can read the complete [[2010_BASC_Call_For_Papers | 2010 BASC CALL FOR PAPERS]].&lt;br /&gt;
&lt;br /&gt;
{{2010_BASC:Footer_Template | Welcome}}&lt;/div&gt;</summary>
		<author><name>Mark A. Arnold</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=2010_BASC_Speakers&amp;diff=93241</id>
		<title>2010 BASC Speakers</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=2010_BASC_Speakers&amp;diff=93241"/>
				<updated>2010-11-18T20:16:28Z</updated>
		
		<summary type="html">&lt;p&gt;Mark A. Arnold: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{2010_BASC:Header_Template | Speakers}}&lt;br /&gt;
__FORCETOC__&lt;br /&gt;
We would like to thank our speakers for donating their time and effort to help make this conference successful and free.&lt;br /&gt;
&lt;br /&gt;
=== Josh Corman (The 451 Group) === &lt;br /&gt;
Joshua Corman is the Research Director of the 451 Group's enterprise security practice. Corman has more than a decade of experience with security and networking software, most recently serving as Principal Security Strategist for IBM Internet Security Systems. Corman’s research cuts across sectors to the core challenges of the industry, and drives evolutionary strategies toward emerging technologies and shifting economics.&lt;br /&gt;
&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
Corman is a candid and highly coveted speaker and has spoken at leading industry events such as RSA, Interop, ISACA, and SANS. His efforts to educate and challenge the industry recently lead NetworkWorld magazine to recognize him as a [http://www.networkworld.com/supp/2009/outlook/010509-tech-people-to-know.html top innovators of IT] for 2009. Corman also serves on the Faculty for IANS and is a staunch advocate for CISOs everywhere. In 2010, Corman also co-founded [http://rugedsoftware.org RuggedSoftware.org] – a value based initiative to raise awareness and usher in an era of secure digital infrastructure.&lt;br /&gt;
&lt;br /&gt;
=== Ming Chow (Tufts University, CS Department) ===&lt;br /&gt;
Ming Chow is a scholar of science and technology and a Lecturer at the Tufts University Department of Computer Science.  His areas of interests are computer security, game development, web application security, and Computer Science in Education. Ming co-edited a special issue of IEEE Security &amp;amp; Privacy on securing online games with Gary McGraw of Cigital, Inc. published in May 2009. Ming is a frequent guest speaker, and have spoke at numerous organizations, including New England Association of Insurance Fraud Investigators (NEAIFI), and the New England Chapter of the High Technology Crime Investigation Association (HTCIA-NE), the Greater Boston Chapter of the Association of Certified Fraud Examiners (ACFE), John Hancock, and the Massachusetts Office of the Attorney General (AGO). Finally, Ming is a SANS GIAC Certified Incident Handler (GCIH).&lt;br /&gt;
'''HTML5  Security'''&amp;lt;br/&amp;gt;&lt;br /&gt;
The power of HTML5 allows developers to create &lt;br /&gt;
web applications not just structured content, but its new features has increased the attack surface.  This presentation will demo and discuss new attack opportunities, particularly on client machines, including abusing the offline application cache and SQL injection via file-based client-side databases.&lt;br /&gt;
&lt;br /&gt;
=== Andrew Gronosky (Raytheon/BBN Technologies) ===&lt;br /&gt;
Mr. Andrew Gronosky is a staff engineer at Raytheon BBN Technologies. He has experience developing software for a variety of applications including data analysis and visualization, digital signal processing, and parallel and distributed systems. He holds a Master of Science degree in mathematics from Rensselaer Polytechnic Institute and is a member of the IEEE and the ACM. &amp;lt;br/&amp;gt;&lt;br /&gt;
'''A Crumple Zone for Service-Oriented Architectures'''&amp;lt;br/&amp;gt;&lt;br /&gt;
We present a new architectural construct analogous to the crumple zone in an automobile.  It consists of a layer of intelligent service proxies that work together to provide both signature-based and non-signature based defenses. We present our initial design &lt;br /&gt;
for Java RMI based services and compare it with  web application firewalls.&lt;br /&gt;
&lt;br /&gt;
=== Joshua &amp;quot;Jabra&amp;quot; Abraham, Will Vandevanter (Rapid7) ===&lt;br /&gt;
Joshua &amp;quot;Jabra&amp;quot; Abraham joined Rapid7 in 2006 as a Security Consultant. Josh has extensive IT Security and Auditing experience and worked as an enterprise risk assessment analyst for Hasbro Corporation. Josh specializes in penetration testing, web application security assessments, wireless security assessments, and custom code development. He has spoken at BlackHat, DefCon, ShmooCon, The SANS Pentest Summit, Infosec World, CSI, OWASP Conferences, LinuxWorld, Comdex and BLUG. In his spare time, he contributes code to open source security projects such as the BackTrack LiveCD, BeEF, Nikto, Fierce, and PBNJ. He is frequently quoted in the media regarding Microsoft Patch Tuesday and web application security by ComputerWorld, DarkReading and SC Magazine.&amp;lt;br/&amp;gt;&lt;br /&gt;
Mr. Vandevanter joined Rapid7 in 2008. Will has IT Security experience with a focus in web application security and secure software engineering. Will specializes in penetration testing, web application security assessments, and secure code development. In the past Will has also worked on a few different Open Source security projects including porting SELinux to OpenMoko and other Linux based mobile platforms. Will holds a Bachelors Degree in Mathematics and Computer Science from McGill University and Masters Degree in Computer Science from James Madison University.&amp;lt;br&amp;gt;&lt;br /&gt;
'''Hacking SAP BusinessObjects'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Business intelligence is a multi-billion industry. At the top of the product food chain is BusinessObjects. BusinessObjects is a very widely deployed business intelligence tool that’s focus is in managing, querying, analyzing, and reporting on business data. It is used by government entities (e.g. U.S Air Force), telecom companies (e.g. Verizon), car manufacturers (e.g. Nissan), and beverage companies (e.g. Coors) to retain and control vast amounts of data. If you are a penetration tester chances are you have run into at least one BusinessObjects server during an engagement. Yet, very few vulnerabilities have been publically released and, to the best of the authors knowledge, no white papers have been released on attack methodologies for BusinessObjects itself. In this presentation we will present the entire lifecycle of attacking a BusinessObjects server from external and internal enumeration (e.g. Google dorks), fingerprinting techniques, account enumeration vulnerabilities, specific attack vectors for gaining access to accounts, privilege escalation vulnerabilities, and eventually full system compromise vulnerabilities that we have found during our research. Anyone interesting in attacking an organization that has BusinessObjects or SOA deployed in their environment should attend this talk.&lt;br /&gt;
&lt;br /&gt;
=== Christien Rioux (SOURCE Conference) ===&lt;br /&gt;
Christien Rioux is co-founder and chief scientist of Veracode, the world's only binary-analysis powered online application risk management service. Prior to Veracode, he was a founder at security consulting firm @stake, a member of the hacker think-tank L0pht Heavy Industries, and a graduate of Massachusetts Institute Of Technology.&lt;br /&gt;
Today, he focuses on algorithms to automate the difficult task of reverse-engineering and analyzing binaries for security vulnerabilities.&amp;lt;br/&amp;gt;&lt;br /&gt;
'''The Exploit Arms Race'''&amp;lt;br/&amp;gt;&lt;br /&gt;
As defenses have become more sophisticated, so have the attacks required to circumvent them. Learn about the roots of techniques like Stack cookies/Stackguard/Run-Time&lt;br /&gt;
Stack Checking, DEP and ASLR, from attacks like trampolining,&lt;br /&gt;
return-oriented programming, the evolution of fuzzing techniques, static and dynamic analysis for attacking and defending software.&lt;br /&gt;
&lt;br /&gt;
=== Paul Schofield (Imperva) ===&lt;br /&gt;
With broad business and technical experience ranging from mergers and acquisitions to incident response and investigations, Paul Schofield is a frequent and energetic public speaker.&lt;br /&gt;
With over fourteen years of experience in Information Security and Risk Management, his diverse background he brings insightful perspectives to security and risk management discussions.&lt;br /&gt;
Paul is currently a Senior Security Engineer with Imperva,  an award winning application Security company.&amp;lt;br/&amp;gt;&lt;br /&gt;
'''Business Logic Attacks – BATs and BLBs'''&amp;lt;br&amp;gt;&lt;br /&gt;
Business logic attacks are a set of legal application transactions that are used to carry out a malicious operation that is not part of normal business practices. This presentation will provide a quick introduction to business logic attacks, their unique characteristics and the motivation behind their uptick. Concluding this session we will discuss using multiple advanced techniques to battle these attacks, rather than relying exclusively on application code.&lt;br /&gt;
&lt;br /&gt;
=== Rob Cheyne (CEO, Safelight Security Advisors) ===&lt;br /&gt;
Rob was one of a select few at security consulting company @stake who regularly led and conducted full-blown enterprise-level architecture assessments for Fortune 500 companies.  Drawing from his experience with dozens of real-world architecture assessments over the past 12 years, and his 20 years as a software developer, architect, and consultant, Rob teaches students to challenge assumptions that frequently lead to long-term security and reliability problems. &amp;lt;br&amp;gt;&lt;br /&gt;
'''OWASP Basics 1 and 2'''&amp;lt;br&amp;gt;&lt;br /&gt;
Rob presents a number of scenarios that walk participants through the basics of SQL injection, XSS and CSRF, along with a few other tricks he has up his sleeve.  Participants will come away with a foundation for further security learning.  Those already knowledgeable on application security issues will learn some new techniques for presenting and teaching this information in a clear, concise and effective manner.&lt;br /&gt;
&lt;br /&gt;
=== John Carmichael (Safelight Security Advisors) ===&lt;br /&gt;
'''Coffee Shop Warfare: Protecting Yourself in Dark Territory'''&amp;lt;br/&amp;gt;&lt;br /&gt;
A lighthearted look at the real threats that people face in personal computing, specifically when connected to unknown network at coffee shops and airports. John will cover many of these threats and discuss tools and best practices everyone can engage in to ensure they protect their machine and information from these risks. &lt;br /&gt;
&lt;br /&gt;
=== Dan Crowley (Core Security)===&lt;br /&gt;
'''URL Enlargement'''&amp;lt;br/&amp;gt;&lt;br /&gt;
URL shorteners are ubiquitous in today's Internet culture. This talk will aim to demonstrate them. Come see what's behind the short URLs: personal documents, parasitic storage, authentication credentials, attacks and more!&lt;br /&gt;
&lt;br /&gt;
=== Kenneth Smith ===&lt;br /&gt;
Ken Smith, CISSP, CISA, GCIH is an Enterprise Information Security Architect with 15 years of experience in the information security space.  He currently leads efforts related to IT risk management, compliance, and privacy for a private $1B e-Commerce, Catalog, and Retail organization.  As a consultant, and former QSA, Ken has an extensive background in PCI DSS and has helped many organizations in the area of strategic planning, assessment, remediation plan development, and security program design. &amp;lt;br/&amp;gt;&lt;br /&gt;
'''Web Applications and Data Tokenization'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Tokenization has become increasingly popular as a method to protect sensitive data and reduce the scope of security requirements such as PCI DSS.  Many solutions now integrate directly with web applications, tokenizing data before it ever reaches internal corporate systems.  As developers, you may be tasked with integrating tokenization into your applications.  If done correctly, this can be a big win for your organization.  This talk will cover the types of tokenization solutions, seeing through the marketing hype and vendor claims, and how to avoid some common mistakes that could greatly reduce tokenizations effectiveness.&lt;br /&gt;
&lt;br /&gt;
=== Zach Lanier (Intrepidus) ===&lt;br /&gt;
Zach Lanier is a Senior Security Consultant with the Intrepidus Group, a&lt;br /&gt;
firm specializing in security assessment services. Zach's areas of focus&lt;br /&gt;
are network and application penetration testing, intrusion analysis, and&lt;br /&gt;
general hackery, with frequent dabbling in security and privacy&lt;br /&gt;
research.&amp;lt;br/&amp;gt;&lt;br /&gt;
'''What's Old Is New Again: An Overview of Mobile Application Security'''&amp;lt;br/&amp;gt;&lt;br /&gt;
The ever-increasing prevalence of mobile devices brings with it a slew&lt;br /&gt;
of security problems. Applications running directly on mobile devices&lt;br /&gt;
(and web apps optimized for mobile clients) are ripe for the picking&lt;br /&gt;
even by unsophisticated attackers. The attack classes that once applied&lt;br /&gt;
to traditional network-facing, fat client, and web applications are now&lt;br /&gt;
valid for mobile apps, as well. Insecure authentication and access&lt;br /&gt;
control; home-grown crypto; and memory management problems are just some&lt;br /&gt;
of the issues resurfacing on this new frontier. This presentation will&lt;br /&gt;
discuss the security of some of the most popular applications running on&lt;br /&gt;
mainstream mobile platforms such as Android, iPhone, Blackberry, and&lt;br /&gt;
Windows Mobile.&lt;br /&gt;
&lt;br /&gt;
=== Shakeel Tufail (Fortify) ===&lt;br /&gt;
Shakeel Tufail is a Federal Practice Manager at Fortify, an HP company, where his responsibilities include refining customer security requirements, managing Fortify product deployments and delivering security services.&lt;br /&gt;
Mr. Tufail brings over 18 years of experience to the IT industry in the areas of network engineering, software development, quality assurance, risk management, and security.&lt;br /&gt;
Recently, he led over 30 enterprise security assessments for DoD and Fortune Top 50 commercial organizations that directly led to improvement of their risk profile.&lt;br /&gt;
Prior to joining Fortify, Mr. Tufail held positions such as Deputy Program Manager for the Pentagon Force Protection Agency, Managing Partner for Insyte, General Manager of CompUSA, and Lead Release Engineer for AOL Time-Warner’s AOL Instant Messenger development team and HOST Servers QA group.&lt;br /&gt;
An active software assurance community member, Mr. Tufail contributes to standards-defining efforts including the Common Weakness Enumeration (CWE), the Common Attack Pattern Enumeration and Classification (CAPEC) and other elements of the Software Assurance Programs of the Department of Homeland Security, NSA, and the Department of Defense. He has accumulated over 25 industry standard certifications and is a member of OWASP, ISACA, ISSA, and IEEE.&lt;br /&gt;
In his spare time, Shakeel enjoys travel, photography, and technical training at local schools. Recently, he hiked the Himalayas to Mt. Everest basecamp.&amp;lt;br/&amp;gt;&lt;br /&gt;
'''Open SAMM (Security Assurance Maturity Model)'''&amp;lt;br/&amp;gt;&lt;br /&gt;
SAMM is an open framework to help organizations formulate and implement a strategy for software security that is tailored to the specific risks facing the organization. The building blocks of the model are the three maturity levels defined for each of the twelve security practices. These define a wide variety of activities to reduce security risks and increase software assurance. Additional details are included to measure successful activity performance, understand the associated assurance benefits, estimate personnel and other costs.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{{2010 BASC:Section Template | Conference Organizers}}&lt;br /&gt;
* Conference Organizer&lt;br /&gt;
** [mailto:jim.weiler@owasp.org Jim Weiler], Chairperson&lt;br /&gt;
* Program Committee: &lt;br /&gt;
** [mailto:mark.arnold@something.somewhere.com Mark Arnold]&lt;br /&gt;
** [mailto:zach.lanier@something.somewhere.com Zach Lanier]&lt;br /&gt;
** [mailto:jim.weiler@owasp.org Jim Weiler], Chairperson&lt;br /&gt;
* Sponsorship Committee: &lt;br /&gt;
** [mailto:mark.arnold@something.somewhere.com Mark Arnold]&lt;br /&gt;
* Website Editor &lt;br /&gt;
** [mailto:neil.smithline@owasp.org Neil Smithline]&lt;br /&gt;
&lt;br /&gt;
{{2010_BASC:Footer_Template | Speakers}}&lt;/div&gt;</summary>
		<author><name>Mark A. Arnold</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=2010_BASC_Agenda&amp;diff=93092</id>
		<title>2010 BASC Agenda</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=2010_BASC_Agenda&amp;diff=93092"/>
				<updated>2010-11-16T19:28:21Z</updated>
		
		<summary type="html">&lt;p&gt;Mark A. Arnold: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{2010_BASC:Header_Template | Agenda}}&lt;br /&gt;
&amp;lt;!-- --------------------------------------------------------------------&lt;br /&gt;
INSTRUCTIONS FOR EDITORS:&lt;br /&gt;
&lt;br /&gt;
Updating this agenda is a 3-step process. First you must convert the existing entries to the&lt;br /&gt;
new format. You can do these one at a time or all at once. Whatever is easiest. Second, you need to&lt;br /&gt;
fill in the data for the presentation. Third, miscellaneous details should be cleaned up.&lt;br /&gt;
&lt;br /&gt;
1) To convert a presentation to the new format:&lt;br /&gt;
  - Most importantly, look at the 10:00 time slot and use it as an example.&lt;br /&gt;
  - Find the time slot you want to modify.&lt;br /&gt;
  - If it already has the Presentation Agenda Template then you are done&lt;br /&gt;
  - Copy: {{2010_BASC:Presentaton_Agenda_Template|TYPE|To Be Determined Presentation|To Be Determined}}&lt;br /&gt;
  - Delete the text that is in the time slot already. This requires great care.&lt;br /&gt;
      You probably want to delete the lines that do not begin with a &lt;br /&gt;
      pipe (|) or an open curly ({).&lt;br /&gt;
  - Paste the text you copied into that time slot.&lt;br /&gt;
  - Replace the word &amp;quot;TYPE&amp;quot; with either &amp;quot;Presentation&amp;quot; or &amp;quot;Keynote&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2) To fill in the appropriate data:&lt;br /&gt;
  - Go to http://www.owasp.org/index.php/2010_BASC_Presentations and add&lt;br /&gt;
    the presentation's abstract. If you don't have an abstract,&lt;br /&gt;
    insert &amp;quot;Presentation abstract will be available shortly.&amp;quot;&lt;br /&gt;
  - Go to http://www.owasp.org/index.php/2010_BASC_Speakers and add the speaker(s) bio.&lt;br /&gt;
    If you don't have bio information, just put the speaker's name into the page and &lt;br /&gt;
    and make their bio &amp;quot;Speaker information will be available shortly.&amp;quot;&lt;br /&gt;
    Until it presents a problem, list multiple speakers as one.&lt;br /&gt;
    For example, &amp;quot;John Boy &amp;amp; Grandpa&amp;quot;.&lt;br /&gt;
  - Find the right slot in the table.&lt;br /&gt;
  - Replace the &amp;quot;To Be Determined Presentation&amp;quot; text in the table&lt;br /&gt;
    with the presentation name __EXACTLY__ as it is on the presentation page.&lt;br /&gt;
  - Replace the &amp;quot;To Be Determined&amp;quot; text in the table&lt;br /&gt;
    with the speaker(s) name(s) __EXACTLY__ as it is on the bio page.&lt;br /&gt;
  &lt;br /&gt;
3) Clean up whatever needs cleaning up.&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------- --&amp;gt;&lt;br /&gt;
{| style=&amp;quot;width:80%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#7B8ABD; color:white&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
&amp;lt;h2&amp;gt;Saturday, November 20&amp;lt;/h2&amp;gt; &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#9BA8CF&amp;quot; align=&amp;quot;center&amp;quot; | 8:00-9:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#D2D2D2&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;div&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;font-size:130%&amp;quot;&amp;gt;'''Breakfast and Registration'''&amp;lt;/span&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
provided by our Platinum Sponsor&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
{| border=&amp;quot;1&amp;quot;&lt;br /&gt;
| [[File:Rapid7LogoSmall.png|300px|link=http://www.rapid7.com|Rapid7]]&lt;br /&gt;
|}&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 09:00-09:50 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#B0B0B0;&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;div style=&amp;quot;margin:10px;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;font-size: 130%&amp;quot;&amp;gt;'''[[2010_BASC_Presentations#Keynote|Keynote: From the Era of Vulnerabiquity to the Rugged Age]]'''&amp;lt;/span&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;font-size: 120%&amp;quot;&amp;gt;[[2010_BASC_Speakers#Josh Corman|Josh Corman]]&amp;lt;/span&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#9BA8CF&amp;quot; | || align=&amp;quot;center&amp;quot; style=&amp;quot;width:30%; background:#CFA49B&amp;quot; | '''Track 1'''&amp;lt;br/&amp;gt;Horace Mann Room&lt;br /&gt;
 | align=&amp;quot;center&amp;quot; style=&amp;quot;width:30%; background:#DFC799;&amp;quot; | '''Track 2'''&amp;lt;br/&amp;gt;Deborah Sampson / Paul Thomas Room&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 10:00-10:50 || style=&amp;quot;width:30%; background:#BC857A&amp;quot; align=&amp;quot;center&amp;quot; |  &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|HTML5 Security|Ming Chow}}&lt;br /&gt;
 | style=&amp;quot;width:30%; background:#BCA57A&amp;quot; align=&amp;quot;center&amp;quot; rowspan=&amp;quot;2&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|OWASP Basics 1 and 2|Robert Cheyne}}&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#9BA8CF&amp;quot; align=&amp;quot;center&amp;quot; | 11:00-11:50 || style=&amp;quot;width:30%; background:#CFA49B&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|A Crumple Zone for Service Oriented Architectures|Andrew Gronosky}}&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 12:00-13:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;span style=&amp;quot;font-size:130%&amp;quot;&amp;gt;'''Lunch'''&amp;lt;/span&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
provided by our platinum sponsor&lt;br /&gt;
{| border=&amp;quot;1&amp;quot;&lt;br /&gt;
|[[File:SI-Banner-238x57.jpg|link=http://www.securityinnovation.com|Security Innovation]]&lt;br /&gt;
|}&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 13:00-13:50 || style=&amp;quot;width:30%; background:#BC857A&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|Hacking SAP BusinessObjects|Joshua Abraham and Will Vandevanter}}&lt;br /&gt;
 | style=&amp;quot;width:30%; background:#DFC799&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|Coffee Shop Warfare:Protecting Yourself in Dark Territory|John Carmichael}}&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 14:00-14:50 || style=&amp;quot;width:30%; background:#CFA49B&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|*Talk Just Added* -TBA|TBA}}&lt;br /&gt;
 | style=&amp;quot;width:30%; background:#DFC799&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|Url Enlargement|Dan Crowley}}&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 15:00-15:50 || style=&amp;quot;width:30%; background:#BC857A&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|Business Logic Attacks - BATs and BLBs|Paul Schofield}}&lt;br /&gt;
 | style=&amp;quot;width:30%; background:#DFC799&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|Web Applications and Data Tokenization|Kenny Smith}}&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 16:00-16:50 || style=&amp;quot;width:30%; background:#CFA49B&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|The Exploit Arms Race|Christien Rioux}}&lt;br /&gt;
 | style=&amp;quot;width:30%; background:#DFC799&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|Open SAMM|Shakeel Tufail}}&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 17:00-17:30 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:30%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;span style=&amp;quot;font-size:130%&amp;quot;&amp;gt;'''Social Time'''&amp;lt;/span&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
provided by our platinum sponsor&lt;br /&gt;
{| border=&amp;quot;1&amp;quot;&lt;br /&gt;
| [[File:boston-2010-source-277x70.jpg|link=http://www.sourceconference.com|SOURCE]]&lt;br /&gt;
|}&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 17:30-18:30 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:30%; background:#D2D2D2&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;span style=&amp;quot;font-size:130%&amp;quot;&amp;gt;'''Expert Panel: Will we ''EVER'' be Secure?'''&amp;lt;/span&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
''&lt;br /&gt;
Moderator:[http://authorurl.com   Rob Cheyne], CEO, Safelight Security Advisors&amp;lt;br&amp;gt;&lt;br /&gt;
Panelist:[http://authorurl.com Josh Corman], Security Analyst, The 451 Group  &amp;lt;br&amp;gt;&lt;br /&gt;
Panelist:[http://authorurl.com Justin Peavey], CISO, Omgeo &amp;lt;br&amp;gt;&lt;br /&gt;
Panelist:[http://authorurl.com Brian Weekes], Linux Infrastructure Lead, GMO&amp;lt;br&amp;gt;&lt;br /&gt;
Panelist:[http://authorurl.com Adriel DeSautels], CTO, NetRagard&amp;lt;br&amp;gt;&lt;br /&gt;
Panelist:[http://authorurl.com Shakeel Tufail], Security Analyst, Fortify&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 18:30-19:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:30%; background:#99FF99&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;span style=&amp;quot;font-size:130%&amp;quot;&amp;gt;'''Wrap Up'''&amp;lt;/span&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
{{2010_BASC:Footer_Template | Agenda}}&lt;/div&gt;</summary>
		<author><name>Mark A. Arnold</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=2010_BASC_Agenda&amp;diff=93071</id>
		<title>2010 BASC Agenda</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=2010_BASC_Agenda&amp;diff=93071"/>
				<updated>2010-11-16T18:36:29Z</updated>
		
		<summary type="html">&lt;p&gt;Mark A. Arnold: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{2010_BASC:Header_Template | Agenda}}&lt;br /&gt;
&amp;lt;!-- --------------------------------------------------------------------&lt;br /&gt;
INSTRUCTIONS FOR EDITORS:&lt;br /&gt;
&lt;br /&gt;
Updating this agenda is a 3-step process. First you must convert the existing entries to the&lt;br /&gt;
new format. You can do these one at a time or all at once. Whatever is easiest. Second, you need to&lt;br /&gt;
fill in the data for the presentation. Third, miscellaneous details should be cleaned up.&lt;br /&gt;
&lt;br /&gt;
1) To convert a presentation to the new format:&lt;br /&gt;
  - Most importantly, look at the 10:00 time slot and use it as an example.&lt;br /&gt;
  - Find the time slot you want to modify.&lt;br /&gt;
  - If it already has the Presentation Agenda Template then you are done&lt;br /&gt;
  - Copy: {{2010_BASC:Presentaton_Agenda_Template|TYPE|To Be Determined Presentation|To Be Determined}}&lt;br /&gt;
  - Delete the text that is in the time slot already. This requires great care.&lt;br /&gt;
      You probably want to delete the lines that do not begin with a &lt;br /&gt;
      pipe (|) or an open curly ({).&lt;br /&gt;
  - Paste the text you copied into that time slot.&lt;br /&gt;
  - Replace the word &amp;quot;TYPE&amp;quot; with either &amp;quot;Presentation&amp;quot; or &amp;quot;Keynote&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2) To fill in the appropriate data:&lt;br /&gt;
  - Go to http://www.owasp.org/index.php/2010_BASC_Presentations and add&lt;br /&gt;
    the presentation's abstract. If you don't have an abstract,&lt;br /&gt;
    insert &amp;quot;Presentation abstract will be available shortly.&amp;quot;&lt;br /&gt;
  - Go to http://www.owasp.org/index.php/2010_BASC_Speakers and add the speaker(s) bio.&lt;br /&gt;
    If you don't have bio information, just put the speaker's name into the page and &lt;br /&gt;
    and make their bio &amp;quot;Speaker information will be available shortly.&amp;quot;&lt;br /&gt;
    Until it presents a problem, list multiple speakers as one.&lt;br /&gt;
    For example, &amp;quot;John Boy &amp;amp; Grandpa&amp;quot;.&lt;br /&gt;
  - Find the right slot in the table.&lt;br /&gt;
  - Replace the &amp;quot;To Be Determined Presentation&amp;quot; text in the table&lt;br /&gt;
    with the presentation name __EXACTLY__ as it is on the presentation page.&lt;br /&gt;
  - Replace the &amp;quot;To Be Determined&amp;quot; text in the table&lt;br /&gt;
    with the speaker(s) name(s) __EXACTLY__ as it is on the bio page.&lt;br /&gt;
  &lt;br /&gt;
3) Clean up whatever needs cleaning up.&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------- --&amp;gt;&lt;br /&gt;
{| style=&amp;quot;width:80%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#7B8ABD; color:white&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
&amp;lt;h2&amp;gt;Saturday, November 20&amp;lt;/h2&amp;gt; &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#9BA8CF&amp;quot; align=&amp;quot;center&amp;quot; | 8:00-9:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#D2D2D2&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;div&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;font-size:130%&amp;quot;&amp;gt;'''Breakfast and Registration'''&amp;lt;/span&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
provided by our Platinum Sponsor&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
{| border=&amp;quot;1&amp;quot;&lt;br /&gt;
| [[File:Rapid7LogoSmall.png|300px|link=http://www.rapid7.com|Rapid7]]&lt;br /&gt;
|}&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 09:00-09:50 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#B0B0B0;&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;div style=&amp;quot;margin:10px;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;font-size: 130%&amp;quot;&amp;gt;'''[[2010_BASC_Presentations#Keynote|Keynote: From the Era of Vulnerabiquity to the Rugged Age]]'''&amp;lt;/span&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;font-size: 120%&amp;quot;&amp;gt;[[2010_BASC_Speakers#Josh Corman|Josh Corman]]&amp;lt;/span&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#9BA8CF&amp;quot; | || align=&amp;quot;center&amp;quot; style=&amp;quot;width:30%; background:#CFA49B&amp;quot; | '''Track 1'''&amp;lt;br/&amp;gt;Horace Mann Room&lt;br /&gt;
 | align=&amp;quot;center&amp;quot; style=&amp;quot;width:30%; background:#DFC799;&amp;quot; | '''Track 2'''&amp;lt;br/&amp;gt;Deborah Sampson / Paul Thomas Room&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 10:00-10:50 || style=&amp;quot;width:30%; background:#BC857A&amp;quot; align=&amp;quot;center&amp;quot; |  &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|HTML5 Security|Ming Chow}}&lt;br /&gt;
 | style=&amp;quot;width:30%; background:#BCA57A&amp;quot; align=&amp;quot;center&amp;quot; rowspan=&amp;quot;2&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|OWASP Basics 1 and 2|Robert Cheyne}}&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#9BA8CF&amp;quot; align=&amp;quot;center&amp;quot; | 11:00-11:50 || style=&amp;quot;width:30%; background:#CFA49B&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|A Crumple Zone for Service Oriented Architectures|Andrew Gronosky}}&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 12:00-13:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;span style=&amp;quot;font-size:130%&amp;quot;&amp;gt;'''Lunch'''&amp;lt;/span&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
provided by our platinum sponsor&lt;br /&gt;
{| border=&amp;quot;1&amp;quot;&lt;br /&gt;
|[[File:SI-Banner-238x57.jpg|link=http://www.securityinnovation.com|Security Innovation]]&lt;br /&gt;
|}&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 13:00-13:50 || style=&amp;quot;width:30%; background:#BC857A&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|Hacking SAP BusinessObjects|Joshua Abraham and Will Vandevanter}}&lt;br /&gt;
 | style=&amp;quot;width:30%; background:#DFC799&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|Coffee Shop Warfare:Protecting Yourself in Dark Territory|John Carmichael}}&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 14:00-14:50 || style=&amp;quot;width:30%; background:#CFA49B&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
 | style=&amp;quot;width:30%; background:#DFC799&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|Url Enlargement|Dan Crowley}}&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 15:00-15:50 || style=&amp;quot;width:30%; background:#BC857A&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|Business Logic Attacks - BATs and BLBs|Paul Schofield}}&lt;br /&gt;
 | style=&amp;quot;width:30%; background:#DFC799&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|Web Applications and Data Tokenization|Kenny Smith}}&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 16:00-16:50 || style=&amp;quot;width:30%; background:#CFA49B&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|The Exploit Arms Race|Christien Rioux}}&lt;br /&gt;
 | style=&amp;quot;width:30%; background:#DFC799&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|Open SAMM|Shakeel Tufail}}&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 17:00-17:30 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:30%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;span style=&amp;quot;font-size:130%&amp;quot;&amp;gt;'''Social Time'''&amp;lt;/span&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
provided by our platinum sponsor&lt;br /&gt;
{| border=&amp;quot;1&amp;quot;&lt;br /&gt;
| [[File:boston-2010-source-277x70.jpg|link=http://www.sourceconference.com|SOURCE]]&lt;br /&gt;
|}&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 17:30-18:30 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:30%; background:#D2D2D2&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;span style=&amp;quot;font-size:130%&amp;quot;&amp;gt;'''Expert Panel: Will we ''EVER'' be Secure?'''&amp;lt;/span&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
''&lt;br /&gt;
Moderator:[http://authorurl.com   Rob Cheyne], CEO, Safelight Security Advisors&amp;lt;br&amp;gt;&lt;br /&gt;
Panelist:[http://authorurl.com Josh Corman], Security Analyst, The 451 Group  &amp;lt;br&amp;gt;&lt;br /&gt;
Panelist:[http://authorurl.com Justin Peavey], CISO, Omgeo &amp;lt;br&amp;gt;&lt;br /&gt;
Panelist:[http://authorurl.com Brian Weekes], Linux Infrastructure Lead, GMO&amp;lt;br&amp;gt;&lt;br /&gt;
Panelist:[http://authorurl.com Adriel DeSautels], CTO, NetRagard&amp;lt;br&amp;gt;&lt;br /&gt;
Panelist:[http://authorurl.com Shakeel Tufail], Security Analyst, Fortify&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 18:30-19:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:30%; background:#99FF99&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;span style=&amp;quot;font-size:130%&amp;quot;&amp;gt;'''Wrap Up'''&amp;lt;/span&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
{{2010_BASC:Footer_Template | Agenda}}&lt;/div&gt;</summary>
		<author><name>Mark A. Arnold</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=2010_BASC_Speakers&amp;diff=93000</id>
		<title>2010 BASC Speakers</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=2010_BASC_Speakers&amp;diff=93000"/>
				<updated>2010-11-15T17:32:52Z</updated>
		
		<summary type="html">&lt;p&gt;Mark A. Arnold: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{2010_BASC:Header_Template | Speakers}}&lt;br /&gt;
__FORCETOC__&lt;br /&gt;
We would like to thank our speakers for donating their time and effort to help make this conference successful and free.&lt;br /&gt;
&lt;br /&gt;
=== Josh Corman (The 451 Group) === &lt;br /&gt;
Joshua Corman is the Research Director of the 451 Group's enterprise security practice. Corman has more than a decade of experience with security and networking software, most recently serving as Principal Security Strategist for IBM Internet Security Systems. Corman’s research cuts across sectors to the core challenges of the industry, and drives evolutionary strategies toward emerging technologies and shifting economics.&lt;br /&gt;
&lt;br /&gt;
Corman is a candid and highly coveted speaker and has spoken at leading industry events such as RSA, Interop, ISACA, and SANS. His efforts to educate and challenge the industry recently lead NetworkWorld magazine to recognize him as a [http://www.networkworld.com/supp/2009/outlook/010509-tech-people-to-know.html top innovators of IT] for 2009. Corman also serves on the Faculty for IANS and is a staunch advocate for CISOs everywhere. In 2010, Corman also co-founded [http://rugedsoftware.org RuggedSoftware.org] – a value based initiative to raise awareness and usher in an era of secure digital infrastructure.&lt;br /&gt;
&lt;br /&gt;
=== Ming Chow (Tufts University, CS Department) ===&lt;br /&gt;
'''HTML5  Security'''&amp;lt;br/&amp;gt;&lt;br /&gt;
The power of HTML5 allows developers to create &lt;br /&gt;
web applications not just structured content, but its new features has increased the attack surface.  This presentation will demo and discuss new attack opportunities, particularly on client machines, including abusing the offline application cache and SQL injection via file-based client-side databases.&lt;br /&gt;
&lt;br /&gt;
=== Andrew Gronosky (Raytheon/BBN Technologies) ===&lt;br /&gt;
'''A Crumple Zone for Service-Oriented Architectures'''&amp;lt;br/&amp;gt;&lt;br /&gt;
We present a new architectural construct analogous to the crumple zone in an automobile.  It consists of a layer of intelligent service proxies that work together to provide both signature-based and non-signature based defenses. We present our initial design &lt;br /&gt;
for Java RMI based services and compare it with  web application firewalls.&lt;br /&gt;
&lt;br /&gt;
=== Joshua &amp;quot;Jabra&amp;quot; Abraham, Will Vandevanter (Rapid7) ===&lt;br /&gt;
'''Hacking SAP BusinessObjects'''&amp;lt;br/&amp;gt;&lt;br /&gt;
BusinessObjects is a very widely deployed business intelligence tool. In this presentation we will present the entire lifecycle of attacking a  BusinessObjects server using vulnerabilities that we have found during our research.&lt;br /&gt;
&lt;br /&gt;
=== Christien Rioux (SOURCE Conference) ===&lt;br /&gt;
'''The Exploit Arms Race'''&amp;lt;br/&amp;gt;&lt;br /&gt;
As defenses have become more sophisticated, so have the attacks required to circumvent them. Learn about the roots of techniques like Stack cookies/Stackguard/Run-Time&lt;br /&gt;
Stack Checking, DEP and ASLR, from attacks like trampolining,&lt;br /&gt;
return-oriented programming, the evolution of fuzzing techniques, static and dynamic analysis for attacking and defending software.&lt;br /&gt;
&lt;br /&gt;
=== Paul Schofield (Imperva) ===&lt;br /&gt;
'''Business Logic Attacks – BATs and BLBs'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Business logic attacks are a set of legal application transactions that are used to carry out a malicious operation that is not part of normal business practices. This presentation will provide a quick introduction to business logic attacks, their unique characteristics and the motivation behind their uptick. Concluding this session we will discuss using multiple advanced techniques to battle these attacks, rather than relying exclusively on application code.&lt;br /&gt;
&lt;br /&gt;
=== Rob Cheyne (Safelight Security Advisors) ===&lt;br /&gt;
'''OWASP Basics 1 and 2'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Rob presents a number of scenarios that walk participants through the basics of SQL injection, XSS and CSRF, along with a few other tricks he has up his sleeve.  Participants will come away with a foundation for further security learning.  Those already knowledgeable on application security issues will learn some new techniques for presenting and teaching this information in a clear, concise and effective manner.&lt;br /&gt;
&lt;br /&gt;
=== John Carmichael (Safelight Security Advisors) ===&lt;br /&gt;
'''Coffee Shop Warfare: Protecting Yourself in Dark Territory'''&amp;lt;br/&amp;gt;&lt;br /&gt;
A lighthearted look at the real threats that people face in personal computing, specifically when connected to unknown network at coffee shops and airports. John will cover many of these threats and discuss tools and best practices everyone can engage in to ensure they protect their machine and information from these risks. &lt;br /&gt;
&lt;br /&gt;
=== Dan Crowley (Core Security)===&lt;br /&gt;
'''URL Enlargement'''&amp;lt;br/&amp;gt;&lt;br /&gt;
URL shorteners are ubiquitous in today's Internet culture. This talk will aim to demonstrate them. Come see what's behind the short URLs: personal documents, parasitic storage, authentication credentials, attacks and more!&lt;br /&gt;
&lt;br /&gt;
=== Kenneth Smith ===&lt;br /&gt;
'''Web Applications and Data Tokenization'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Tokenization has become increasingly popular as a method to protect sensitive data and reduce the scope of security requirements such as PCI DSS.  Many solutions now integrate directly with web applications, tokenizing data before it ever reaches internal corporate systems.  As developers, you may be tasked with integrating tokenization into your applications.  If done correctly, this can be a big win for your organization.  This talk will cover the types of tokenization solutions, seeing through the marketing hype and vendor claims, and how to avoid some common mistakes that could greatly reduce tokenizations effectiveness.   &lt;br /&gt;
&lt;br /&gt;
=== Shakeel Tufail (Fortify) ===&lt;br /&gt;
'''Open SAMM (Security Assurance Maturity Model)'''&amp;lt;br/&amp;gt;&lt;br /&gt;
SAMM is an open framework to help organizations formulate and implement a strategy for software security that is tailored to the specific risks facing the organization. The building blocks of the model are the three maturity levels defined for each of the twelve security practices. These define a wide variety of activities to reduce security risks and increase software assurance. Additional details are included to measure successful activity performance, understand the associated assurance benefits, estimate personnel and other costs.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{{2010 BASC:Section Template | Conference Organizers}}&lt;br /&gt;
* Conference Organizer&lt;br /&gt;
** [mailto:jim.weiler@owasp.org Jim Weiler], Chairperson&lt;br /&gt;
* Program Committee: &lt;br /&gt;
** [mailto:mark.arnold@something.somewhere.com Mark Arnold]&lt;br /&gt;
** [mailto:zach.lanier@something.somewhere.com Zach Lanier]&lt;br /&gt;
** [mailto:jim.weiler@owasp.org Jim Weiler], Chairperson&lt;br /&gt;
* Sponsorship Committee: &lt;br /&gt;
** [mailto:mark.arnold@something.somewhere.com Mark Arnold]&lt;br /&gt;
* Website Editor &lt;br /&gt;
** [mailto:neil.smithline@owasp.org Neil Smithline]&lt;br /&gt;
&lt;br /&gt;
{{2010_BASC:Footer_Template | Speakers}}&lt;/div&gt;</summary>
		<author><name>Mark A. Arnold</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=2010_BASC_Speakers&amp;diff=92999</id>
		<title>2010 BASC Speakers</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=2010_BASC_Speakers&amp;diff=92999"/>
				<updated>2010-11-15T17:31:50Z</updated>
		
		<summary type="html">&lt;p&gt;Mark A. Arnold: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{2010_BASC:Header_Template | Speakers}}&lt;br /&gt;
__FORCETOC__&lt;br /&gt;
We would like to thank our speakers for donating their time and effort to help make this conference successful and free.&lt;br /&gt;
&lt;br /&gt;
=== Josh Corman === &lt;br /&gt;
Joshua Corman is the Research Director of the 451 Group's enterprise security practice. Corman has more than a decade of experience with security and networking software, most recently serving as Principal Security Strategist for IBM Internet Security Systems. Corman’s research cuts across sectors to the core challenges of the industry, and drives evolutionary strategies toward emerging technologies and shifting economics.&lt;br /&gt;
&lt;br /&gt;
Corman is a candid and highly coveted speaker and has spoken at leading industry events such as RSA, Interop, ISACA, and SANS. His efforts to educate and challenge the industry recently lead NetworkWorld magazine to recognize him as a [http://www.networkworld.com/supp/2009/outlook/010509-tech-people-to-know.html top innovators of IT] for 2009. Corman also serves on the Faculty for IANS and is a staunch advocate for CISOs everywhere. In 2010, Corman also co-founded [http://rugedsoftware.org RuggedSoftware.org] – a value based initiative to raise awareness and usher in an era of secure digital infrastructure.&lt;br /&gt;
&lt;br /&gt;
=== Ming Chow (Tufts University, CS Department) ===&lt;br /&gt;
'''HTML5  Security'''&amp;lt;br/&amp;gt;&lt;br /&gt;
The power of HTML5 allows developers to create &lt;br /&gt;
web applications not just structured content, but its new features has increased the attack surface.  This presentation will demo and discuss new attack opportunities, particularly on client machines, including abusing the offline application cache and SQL injection via file-based client-side databases.&lt;br /&gt;
&lt;br /&gt;
=== Andrew Gronosky (Raytheon/BBN Technologies) ===&lt;br /&gt;
'''A Crumple Zone for Service-Oriented Architectures'''&amp;lt;br/&amp;gt;&lt;br /&gt;
We present a new architectural construct analogous to the crumple zone in an automobile.  It consists of a layer of intelligent service proxies that work together to provide both signature-based and non-signature based defenses. We present our initial design &lt;br /&gt;
for Java RMI based services and compare it with  web application firewalls.&lt;br /&gt;
&lt;br /&gt;
=== Joshua &amp;quot;Jabra&amp;quot; Abraham, Will Vandevanter (Rapid7) ===&lt;br /&gt;
'''Hacking SAP BusinessObjects'''&amp;lt;br/&amp;gt;&lt;br /&gt;
BusinessObjects is a very widely deployed business intelligence tool. In this presentation we will present the entire lifecycle of attacking a  BusinessObjects server using vulnerabilities that we have found during our research.&lt;br /&gt;
&lt;br /&gt;
=== Christien Rioux (SOURCE Conference) ===&lt;br /&gt;
'''The Exploit Arms Race'''&amp;lt;br/&amp;gt;&lt;br /&gt;
As defenses have become more sophisticated, so have the attacks required to circumvent them. Learn about the roots of techniques like Stack cookies/Stackguard/Run-Time&lt;br /&gt;
Stack Checking, DEP and ASLR, from attacks like trampolining,&lt;br /&gt;
return-oriented programming, the evolution of fuzzing techniques, static and dynamic analysis for attacking and defending software.&lt;br /&gt;
&lt;br /&gt;
=== Paul Schofield (Imperva) ===&lt;br /&gt;
'''Business Logic Attacks – BATs and BLBs'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Business logic attacks are a set of legal application transactions that are used to carry out a malicious operation that is not part of normal business practices. This presentation will provide a quick introduction to business logic attacks, their unique characteristics and the motivation behind their uptick. Concluding this session we will discuss using multiple advanced techniques to battle these attacks, rather than relying exclusively on application code.&lt;br /&gt;
&lt;br /&gt;
=== Rob Cheyne (Safelight Security Advisors) ===&lt;br /&gt;
'''OWASP Basics 1 and 2'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Rob presents a number of scenarios that walk participants through the basics of SQL injection, XSS and CSRF, along with a few other tricks he has up his sleeve.  Participants will come away with a foundation for further security learning.  Those already knowledgeable on application security issues will learn some new techniques for presenting and teaching this information in a clear, concise and effective manner.&lt;br /&gt;
&lt;br /&gt;
=== John Carmichael (Safelight Security Advisors) ===&lt;br /&gt;
'''Coffee Shop Warfare: Protecting Yourself in Dark Territory'''&amp;lt;br/&amp;gt;&lt;br /&gt;
A lighthearted look at the real threats that people face in personal computing, specifically when connected to unknown network at coffee shops and airports. John will cover many of these threats and discuss tools and best practices everyone can engage in to ensure they protect their machine and information from these risks. &lt;br /&gt;
&lt;br /&gt;
=== Dan Crowley (Core Security)===&lt;br /&gt;
'''URL Enlargement'''&amp;lt;br/&amp;gt;&lt;br /&gt;
URL shorteners are ubiquitous in today's Internet culture. This talk will aim to demonstrate them. Come see what's behind the short URLs: personal documents, parasitic storage, authentication credentials, attacks and more!&lt;br /&gt;
&lt;br /&gt;
=== Kenneth Smith ===&lt;br /&gt;
'''Web Applications and Data Tokenization'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Tokenization has become increasingly popular as a method to protect sensitive data and reduce the scope of security requirements such as PCI DSS.  Many solutions now integrate directly with web applications, tokenizing data before it ever reaches internal corporate systems.  As developers, you may be tasked with integrating tokenization into your applications.  If done correctly, this can be a big win for your organization.  This talk will cover the types of tokenization solutions, seeing through the marketing hype and vendor claims, and how to avoid some common mistakes that could greatly reduce tokenizations effectiveness.   &lt;br /&gt;
&lt;br /&gt;
=== Shakeel Tufail (Fortify) ===&lt;br /&gt;
'''Open SAMM (Security Assurance Maturity Model)'''&amp;lt;br/&amp;gt;&lt;br /&gt;
SAMM is an open framework to help organizations formulate and implement a strategy for software security that is tailored to the specific risks facing the organization. The building blocks of the model are the three maturity levels defined for each of the twelve security practices. These define a wide variety of activities to reduce security risks and increase software assurance. Additional details are included to measure successful activity performance, understand the associated assurance benefits, estimate personnel and other costs.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{{2010 BASC:Section Template | Conference Organizers}}&lt;br /&gt;
* Conference Organizer&lt;br /&gt;
** [mailto:jim.weiler@owasp.org Jim Weiler], Chairperson&lt;br /&gt;
* Program Committee: &lt;br /&gt;
** [mailto:mark.arnold@something.somewhere.com Mark Arnold]&lt;br /&gt;
** [mailto:zach.lanier@something.somewhere.com Zach Lanier]&lt;br /&gt;
** [mailto:jim.weiler@owasp.org Jim Weiler], Chairperson&lt;br /&gt;
* Sponsorship Committee: &lt;br /&gt;
** [mailto:mark.arnold@something.somewhere.com Mark Arnold]&lt;br /&gt;
* Website Editor &lt;br /&gt;
** [mailto:neil.smithline@owasp.org Neil Smithline]&lt;br /&gt;
&lt;br /&gt;
{{2010_BASC:Footer_Template | Speakers}}&lt;/div&gt;</summary>
		<author><name>Mark A. Arnold</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=2010_BASC_Speakers&amp;diff=92988</id>
		<title>2010 BASC Speakers</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=2010_BASC_Speakers&amp;diff=92988"/>
				<updated>2010-11-15T17:15:40Z</updated>
		
		<summary type="html">&lt;p&gt;Mark A. Arnold: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{2010_BASC:Header_Template | Speakers}}&lt;br /&gt;
__FORCETOC__&lt;br /&gt;
We would like to thank our speakers for donating their time and effort to help make this conference successful and free.&lt;br /&gt;
&lt;br /&gt;
=== Josh Corman === &lt;br /&gt;
Joshua Corman is the Research Director of the 451 Group's enterprise security practice. Corman has more than a decade of experience with security and networking software, most recently serving as Principal Security Strategist for IBM Internet Security Systems. Corman’s research cuts across sectors to the core challenges of the industry, and drives evolutionary strategies toward emerging technologies and shifting economics.&lt;br /&gt;
&lt;br /&gt;
Corman is a candid and highly coveted speaker and has spoken at leading industry events such as RSA, Interop, ISACA, and SANS. His efforts to educate and challenge the industry recently lead NetworkWorld magazine to recognize him as a [http://www.networkworld.com/supp/2009/outlook/010509-tech-people-to-know.html top innovators of IT] for 2009. Corman also serves on the Faculty for IANS and is a staunch advocate for CISOs everywhere. In 2010, Corman also co-founded [http://rugedsoftware.org RuggedSoftware.org] – a value based initiative to raise awareness and usher in an era of secure digital infrastructure.&lt;br /&gt;
&lt;br /&gt;
=== Ming Chow (Tufts University, CS Department) ===&lt;br /&gt;
'''HTML5  Security'''&amp;lt;br/&amp;gt;&lt;br /&gt;
The power of HTML5 allows developers to create &lt;br /&gt;
web applications not just structured content, but its new features has increased the attack surface.  It has been demonstrated that the HTML5 offline application cache can be abused. The support for file-based client-side databases will open up the opportunity for SQL injection attack on client machines.&lt;br /&gt;
&lt;br /&gt;
=== Andrew Gronosky (Raytheon/BBN Technologies) ===&lt;br /&gt;
'''A Crumple Zone for Service-Oriented Architectures'''&amp;lt;br/&amp;gt;&lt;br /&gt;
We present a new architectural construct analogous to the crumple zone in an automobile.  It consists of a layer of intelligent service proxies that work together to provide both signature-based and non-signature based defenses. We present our initial design &lt;br /&gt;
for Java RMI based services and compare it with  web application firewalls.&lt;br /&gt;
&lt;br /&gt;
=== Joshua &amp;quot;Jabra&amp;quot; Abraham, Will Vandevanter (Rapid7) ===&lt;br /&gt;
'''Hacking SAP BusinessObjects'''&amp;lt;br/&amp;gt;&lt;br /&gt;
BusinessObjects is a very widely deployed business intelligence tool. In this presentation we will present the entire lifecycle of attacking a  BusinessObjects server using vulnerabilities that we have found during our research.&lt;br /&gt;
&lt;br /&gt;
=== Christien Rioux (SOURCE Conference) ===&lt;br /&gt;
'''The Exploit Arms Race'''&amp;lt;br/&amp;gt;&lt;br /&gt;
As defenses have become more sophisticated, so have the attacks required to circumvent them. Learn about the roots of techniques like Stack cookies/Stackguard/Run-Time&lt;br /&gt;
Stack Checking, DEP and ASLR, from attacks like trampolining,&lt;br /&gt;
return-oriented programming, the evolution of fuzzing techniques, static and dynamic analysis for attacking and defending software.&lt;br /&gt;
&lt;br /&gt;
=== Paul Schofield (Imperva) ===&lt;br /&gt;
'''Business Logic Attacks – BATs and BLBs'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Business logic attacks are a set of legal application transactions that are used to carry out a malicious operation that is not part of normal business practices. This presentation will provide a quick introduction to business logic attacks, their unique characteristics and the motivation behind their uptick. . Concluding this session we will discuss  &amp;quot;virtual patching&amp;quot; using a web application firewall, rather than fixing the application code.&lt;br /&gt;
&lt;br /&gt;
=== Rob Cheyne (Safelight Security Advisors) ===&lt;br /&gt;
'''OWASP Basics 1 and 2'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Rob presents a number of scenarios that walk participants through the basics of SQL injection, XSS and CSRF, along with a few other tricks he has up his sleeve.  Participants will come away with the basic building blocks of knowledge required to create a foundation for further security learning. Participants already knowledgeable on security may learn some new techniques for presenting and teaching this information.&lt;br /&gt;
&lt;br /&gt;
=== John Carmichael (Safelight Security Advisors) ===&lt;br /&gt;
'''Coffee Shop Warfare: Protecting Yourself in Dark Territory'''&amp;lt;br/&amp;gt;&lt;br /&gt;
A lighthearted look at the real threats that people face in personal computing, specifically when connected to unknown network at coffee shops and airports. John will cover many of these threats and discuss tools and best practices everyone can engage in to ensure they protect their machine and information from these risks. &lt;br /&gt;
&lt;br /&gt;
=== Dan Crowley (Core Security)===&lt;br /&gt;
'''URL Enlargement'''&amp;lt;br/&amp;gt;&lt;br /&gt;
URL shorteners are ubiquitous in today's Internet culture. This talk will aim to demonstrate them. Come see what's behind the short URLs: personal documents, parasitic storage, authentication credentials, attacks and more!&lt;br /&gt;
&lt;br /&gt;
=== Kenneth Smith ===&lt;br /&gt;
'''Web Applications and Data Tokenization'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Tokenization benefits, drawbacks, work involved, seeing through the vendors claims, some big gotchas to avoid, and realizing ultimate value. See where tokenization makes sense and where it doesn't.&lt;br /&gt;
&lt;br /&gt;
=== Shakeel Tufail (Fortify) ===&lt;br /&gt;
'''Open SAMM (Security Assurance Maturity Model)'''&amp;lt;br/&amp;gt;&lt;br /&gt;
SAMM is an open framework to help organizations formulate and implement a strategy for software security that is tailored to the specific risks facing the organization. The building blocks of the model are the three maturity levels defined for each of the twelve security practices. These define a wide variety of activities to reduce security risks and increase software assurance. Additional details are included to measure successful activity performance, understand the associated assurance benefits, estimate personnel and other costs.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{{2010 BASC:Section Template | Conference Organizers}}&lt;br /&gt;
* Conference Organizer&lt;br /&gt;
** [mailto:jim.weiler@owasp.org Jim Weiler], Chairperson&lt;br /&gt;
* Program Committee: &lt;br /&gt;
** [mailto:mark.arnold@something.somewhere.com Mark Arnold]&lt;br /&gt;
** [mailto:zach.lanier@something.somewhere.com Zach Lanier]&lt;br /&gt;
** [mailto:jim.weiler@owasp.org Jim Weiler], Chairperson&lt;br /&gt;
* Sponsorship Committee: &lt;br /&gt;
** [mailto:mark.arnold@something.somewhere.com Mark Arnold]&lt;br /&gt;
* Website Editor &lt;br /&gt;
** [mailto:neil.smithline@owasp.org Neil Smithline]&lt;br /&gt;
&lt;br /&gt;
{{2010_BASC:Footer_Template | Speakers}}&lt;/div&gt;</summary>
		<author><name>Mark A. Arnold</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=2010_BASC_Speakers&amp;diff=92981</id>
		<title>2010 BASC Speakers</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=2010_BASC_Speakers&amp;diff=92981"/>
				<updated>2010-11-15T17:08:57Z</updated>
		
		<summary type="html">&lt;p&gt;Mark A. Arnold: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{2010_BASC:Header_Template | Speakers}}&lt;br /&gt;
__FORCETOC__&lt;br /&gt;
We would like to thank our speakers for donating their time and effort to help make this conference successful and free.&lt;br /&gt;
&lt;br /&gt;
=== Josh Corman === &lt;br /&gt;
Joshua Corman is the Research Director of the 451 Group's enterprise security practice. Corman has more than a decade of experience with security and networking software, most recently serving as Principal Security Strategist for IBM Internet Security Systems. Corman’s research cuts across sectors to the core challenges of the industry, and drives evolutionary strategies toward emerging technologies and shifting economics.&lt;br /&gt;
&lt;br /&gt;
Corman is a candid and highly coveted speaker and has spoken at leading industry events such as RSA, Interop, ISACA, and SANS. His efforts to educate and challenge the industry recently lead NetworkWorld magazine to recognize him as a [http://www.networkworld.com/supp/2009/outlook/010509-tech-people-to-know.html top innovators of IT] for 2009. Corman also serves on the Faculty for IANS and is a staunch advocate for CISOs everywhere. In 2010, Corman also co-founded [http://rugedsoftware.org RuggedSoftware.org] – a value based initiative to raise awareness and usher in an era of secure digital infrastructure.&lt;br /&gt;
&lt;br /&gt;
=== Ming Chow (Tufts University, CS Department) ===&lt;br /&gt;
'''HTML5  Security'''&amp;lt;br/&amp;gt;&lt;br /&gt;
The power of HTML5 allows developers to create &lt;br /&gt;
web applications not just structured content, but its new features has increased the attack surface.  It has been demonstrated that the HTML5 offline application cache can be abused. The support for file-based client-side databases will open up the opportunity for SQL injection attack on client machines.&lt;br /&gt;
&lt;br /&gt;
=== Andrew Gronosky ===&lt;br /&gt;
'''A Crumple Zone for Service-Oriented Architectures'''&amp;lt;br/&amp;gt;&lt;br /&gt;
We present a new architectural construct analogous to the crumple zone in an automobile.  It consists of a layer of intelligent service proxies that work together to provide both signature-based and non-signature based defenses. We present our initial design &lt;br /&gt;
for Java RMI based services and compare it with  web application firewalls.&lt;br /&gt;
&lt;br /&gt;
=== Joshua &amp;quot;Jabra&amp;quot; Abraham, Will Vandevanter (Rapid7) ===&lt;br /&gt;
'''Hacking SAP BusinessObjects'''&amp;lt;br/&amp;gt;&lt;br /&gt;
BusinessObjects is a very widely deployed business intelligence tool. In this presentation we will present the entire lifecycle of attacking a  BusinessObjects server using vulnerabilities that we have found during our research.&lt;br /&gt;
&lt;br /&gt;
=== Christien Rioux (SOURCE Conference) ===&lt;br /&gt;
'''The Exploit Arms Race'''&amp;lt;br/&amp;gt;&lt;br /&gt;
As defenses have become more sophisticated, so have the attacks required to circumvent them. Learn about the roots of techniques like Stack cookies/Stackguard/Run-Time&lt;br /&gt;
Stack Checking, DEP and ASLR, from attacks like trampolining,&lt;br /&gt;
return-oriented programming, the evolution of fuzzing techniques, static and dynamic analysis for attacking and defending software.&lt;br /&gt;
&lt;br /&gt;
=== Paul Schofield (Imperva) ===&lt;br /&gt;
'''Business Logic Attacks – BATs and BLBs'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Business logic attacks are a set of legal application transactions that are used to carry out a malicious operation that is not part of normal business practices. This presentation will provide a quick introduction to business logic attacks, their unique characteristics and the motivation behind their uptick. . Concluding this session we will discuss  &amp;quot;virtual patching&amp;quot; using a web application firewall, rather than fixing the application code.&lt;br /&gt;
&lt;br /&gt;
=== Rob Cheyne (Safelight Security Advisors) ===&lt;br /&gt;
'''OWASP Basics 1 and 2'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Rob presents a number of scenarios that walk participants through the basics of SQL injection, XSS and CSRF, along with a few other tricks he has up his sleeve.  Participants will come away with the basic building blocks of knowledge required to create a foundation for further security learning. Participants already knowledgeable on security may learn some new techniques for presenting and teaching this information.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== John Carmichael (Safelight Security Advisors) ===&lt;br /&gt;
'''Coffee Shop Warfare: Protecting Yourself in Dark Territory'''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Dan Crowley (Core Security)===&lt;br /&gt;
'''URL Enlargement'''&amp;lt;br/&amp;gt;&lt;br /&gt;
URL shorteners are ubiquitous in today's Internet culture. This talk will aim to demonstrate them. Come see what's behind the short URLs: personal documents, parasitic storage, authentication credentials, attacks and more!&lt;br /&gt;
&lt;br /&gt;
=== Kenneth Smith ===&lt;br /&gt;
'''Web Applications and Data Tokenization'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Tokenization benefits, drawbacks, work involved, seeing through the vendors claims, some big gotchas to avoid, and realizing ultimate value. See where tokenization makes sense and where it doesn't.&lt;br /&gt;
&lt;br /&gt;
=== Shakeel Tufail (Fortify) ===&lt;br /&gt;
'''Open SAMM (Security Assurance Maturity Model)'''&amp;lt;br/&amp;gt;&lt;br /&gt;
SAMM is an open framework to help organizations formulate and implement a strategy for software security that is tailored to the specific risks facing the organization. The building blocks of the model are the three maturity levels defined for each of the twelve security practices. These define a wide variety of activities to reduce security risks and increase software assurance. Additional details are included to measure successful activity performance, understand the associated assurance benefits, estimate personnel and other costs.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{{2010 BASC:Section Template | Conference Organizers}}&lt;br /&gt;
* Conference Organizer&lt;br /&gt;
** [mailto:jim.weiler@owasp.org Jim Weiler], Chairperson&lt;br /&gt;
* Program Committee: &lt;br /&gt;
** [mailto:mark.arnold@something.somewhere.com Mark Arnold]&lt;br /&gt;
** [mailto:zach.lanier@something.somewhere.com Zach Lanier]&lt;br /&gt;
** [mailto:jim.weiler@owasp.org Jim Weiler], Chairperson&lt;br /&gt;
* Sponsorship Committee: &lt;br /&gt;
** [mailto:mark.arnold@something.somewhere.com Mark Arnold]&lt;br /&gt;
* Website Editor &lt;br /&gt;
** [mailto:neil.smithline@owasp.org Neil Smithline]&lt;br /&gt;
&lt;br /&gt;
{{2010_BASC:Footer_Template | Speakers}}&lt;/div&gt;</summary>
		<author><name>Mark A. Arnold</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=2010_BASC_Speakers&amp;diff=92979</id>
		<title>2010 BASC Speakers</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=2010_BASC_Speakers&amp;diff=92979"/>
				<updated>2010-11-15T16:58:33Z</updated>
		
		<summary type="html">&lt;p&gt;Mark A. Arnold: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{2010_BASC:Header_Template | Speakers}}&lt;br /&gt;
__FORCETOC__&lt;br /&gt;
We would like to thank our speakers for donating their time and effort to help make this conference successful and free.&lt;br /&gt;
&lt;br /&gt;
=== Josh Corman === &lt;br /&gt;
Joshua Corman is the Research Director of the 451 Group's enterprise security practice. Corman has more than a decade of experience with security and networking software, most recently serving as Principal Security Strategist for IBM Internet Security Systems. Corman’s research cuts across sectors to the core challenges of the industry, and drives evolutionary strategies toward emerging technologies and shifting economics.&lt;br /&gt;
&lt;br /&gt;
Corman is a candid and highly coveted speaker and has spoken at leading industry events such as RSA, Interop, ISACA, and SANS. His efforts to educate and challenge the industry recently lead NetworkWorld magazine to recognize him as a [http://www.networkworld.com/supp/2009/outlook/010509-tech-people-to-know.html top innovators of IT] for 2009. Corman also serves on the Faculty for IANS and is a staunch advocate for CISOs everywhere. In 2010, Corman also co-founded [http://rugedsoftware.org RuggedSoftware.org] – a value based initiative to raise awareness and usher in an era of secure digital infrastructure.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Ming Chow (Tufts University, CS Department) ===&lt;br /&gt;
'''HTML5  Security'''&lt;br /&gt;
The power of HTML5 allows developers to create &lt;br /&gt;
web applications not just structured content, but its new features has increased the attack surface.  It has been demonstrated that the HTML5 offline application cache can be abused. The support for file-based client-side databases will open up the opportunity for SQL injection attack on client machines.&lt;br /&gt;
&lt;br /&gt;
=== Andrew Gronosky ===&lt;br /&gt;
'''A Crumple Zone for Service-Oriented Architectures'''&lt;br /&gt;
We present a new architectural construct analogous to the crumple zone in an automobile.  It consists of a layer of intelligent service proxies that work together to provide both signature-based and non-signature based defenses. We present our initial design &lt;br /&gt;
for Java RMI based services and compare it with  web application firewalls.&lt;br /&gt;
&lt;br /&gt;
=== Joshua &amp;quot;Jabra&amp;quot; Abraham, Will Vandevanter (Rapid7) ===&lt;br /&gt;
'''Hacking SAP BusinessObjects'''&lt;br /&gt;
BusinessObjects is a very widely deployed business intelligence tool. In this presentation we will present the entire lifecycle of attacking a  BusinessObjects server using vulnerabilities that we have found during our research.&lt;br /&gt;
&lt;br /&gt;
=== Christien Rioux (SOURCE Conference) ===&lt;br /&gt;
'''The Exploit Arms Race'''&lt;br /&gt;
As defenses have become more sophisticated, so have the attacks required to circumvent them. Learn about the roots of techniques like Stack cookies/Stackguard/Run-Time&lt;br /&gt;
Stack Checking, DEP and ASLR, from attacks like trampolining,&lt;br /&gt;
return-oriented programming, the evolution of fuzzing techniques, static and dynamic analysis for attacking and defending software.&lt;br /&gt;
&lt;br /&gt;
=== Paul Schofield (Imperva) ===&lt;br /&gt;
'''Business Logic Attacks – BATs and BLBs'''&lt;br /&gt;
Business logic attacks are a set of legal application transactions that are used to carry out a malicious operation that is not part of normal business practices. This presentation will provide a quick introduction to business logic attacks, their unique characteristics and the motivation behind their uptick. . Concluding this session we will discuss  &amp;quot;virtual patching&amp;quot; using a web application firewall, rather than fixing the application code.&lt;br /&gt;
&lt;br /&gt;
=== To Be Determined === &lt;br /&gt;
Lots of interesting facts about this really good speaker. By the time you are done reading this you will be OOO-ing and AHH-ing without control. You'll be so impressed that you will flip head-over-heel.&lt;br /&gt;
&lt;br /&gt;
{{2010 BASC:Section Template | Conference Organizers}}&lt;br /&gt;
* Conference Organizer&lt;br /&gt;
** [mailto:jim.weiler@owasp.org Jim Weiler], Chairperson&lt;br /&gt;
* Program Committee: &lt;br /&gt;
** [mailto:mark.arnold@something.somewhere.com Mark Arnold]&lt;br /&gt;
** [mailto:zach.lanier@something.somewhere.com Zach Lanier]&lt;br /&gt;
** [mailto:jim.weiler@owasp.org Jim Weiler], Chairperson&lt;br /&gt;
* Sponsorship Committee: &lt;br /&gt;
** [mailto:mark.arnold@something.somewhere.com Mark Arnold]&lt;br /&gt;
* Website Editor &lt;br /&gt;
** [mailto:neil.smithline@owasp.org Neil Smithline]&lt;br /&gt;
&lt;br /&gt;
{{2010_BASC:Footer_Template | Speakers}}&lt;/div&gt;</summary>
		<author><name>Mark A. Arnold</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=2010_BASC_Agenda&amp;diff=92970</id>
		<title>2010 BASC Agenda</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=2010_BASC_Agenda&amp;diff=92970"/>
				<updated>2010-11-15T08:26:41Z</updated>
		
		<summary type="html">&lt;p&gt;Mark A. Arnold: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{2010_BASC:Header_Template | Agenda}}&lt;br /&gt;
&amp;lt;!-- --------------------------------------------------------------------&lt;br /&gt;
INSTRUCTIONS FOR EDITORS:&lt;br /&gt;
&lt;br /&gt;
Updating this agenda is a 3-step process. First you must convert the existing entries to the&lt;br /&gt;
new format. You can do these one at a time or all at once. Whatever is easiest. Second, you need to&lt;br /&gt;
fill in the data for the presentation. Third, miscellaneous details should be cleaned up.&lt;br /&gt;
&lt;br /&gt;
1) To convert a presentation to the new format:&lt;br /&gt;
  - Most importantly, look at the 10:00 time slot and use it as an example.&lt;br /&gt;
  - Find the time slot you want to modify.&lt;br /&gt;
  - If it already has the Presentation Agenda Template then you are done&lt;br /&gt;
  - Copy: {{2010_BASC:Presentaton_Agenda_Template|TYPE|To Be Determined Presentation|To Be Determined}}&lt;br /&gt;
  - Delete the text that is in the time slot already. This requires great care.&lt;br /&gt;
      You probably want to delete the lines that do not begin with a &lt;br /&gt;
      pipe (|) or an open curly ({).&lt;br /&gt;
  - Paste the text you copied into that time slot.&lt;br /&gt;
  - Replace the word &amp;quot;TYPE&amp;quot; with either &amp;quot;Presentation&amp;quot; or &amp;quot;Keynote&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2) To fill in the appropriate data:&lt;br /&gt;
  - Go to http://www.owasp.org/index.php/2010_BASC_Presentations and add&lt;br /&gt;
    the presentation's abstract. If you don't have an abstract,&lt;br /&gt;
    insert &amp;quot;Presentation abstract will be available shortly.&amp;quot;&lt;br /&gt;
  - Go to http://www.owasp.org/index.php/2010_BASC_Speakers and add the speaker(s) bio.&lt;br /&gt;
    If you don't have bio information, just put the speaker's name into the page and &lt;br /&gt;
    and make their bio &amp;quot;Speaker information will be available shortly.&amp;quot;&lt;br /&gt;
    Until it presents a problem, list multiple speakers as one.&lt;br /&gt;
    For example, &amp;quot;John Boy &amp;amp; Grandpa&amp;quot;.&lt;br /&gt;
  - Find the right slot in the table.&lt;br /&gt;
  - Replace the &amp;quot;To Be Determined Presentation&amp;quot; text in the table&lt;br /&gt;
    with the presentation name __EXACTLY__ as it is on the presentation page.&lt;br /&gt;
  - Replace the &amp;quot;To Be Determined&amp;quot; text in the table&lt;br /&gt;
    with the speaker(s) name(s) __EXACTLY__ as it is on the bio page.&lt;br /&gt;
  &lt;br /&gt;
3) Clean up whatever needs cleaning up.&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------- --&amp;gt;&lt;br /&gt;
{| style=&amp;quot;width:80%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#7B8ABD; color:white&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
&amp;lt;h2&amp;gt;Saturday, November 20&amp;lt;/h2&amp;gt; &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#9BA8CF&amp;quot; align=&amp;quot;center&amp;quot; | 8:00-9:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#D2D2D2&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;div&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;font-size:140%&amp;quot;&amp;gt;'''Breakfast and Registration'''&amp;lt;/span&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
provided by our Platinum Sponsor&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
{| border=&amp;quot;1&amp;quot;&lt;br /&gt;
| [[File:Rapid7LogoSmall.png|300px|link=http://www.rapid7.com|Rapid7]]&lt;br /&gt;
|}&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 09:00-09:50 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#B0B0B0;&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;div style=&amp;quot;margin:10px;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;font-size: 140%&amp;quot;&amp;gt;'''[[2010_BASC_Presentations#Keynote|Keynote: From the Era of Vulnerabiquity to the Rugged Age]]'''&amp;lt;/span&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;font-size: 120%&amp;quot;&amp;gt;[[2010_BASC_Speakers#Josh Corman|Josh Corman]]&amp;lt;/span&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#9BA8CF&amp;quot; | || align=&amp;quot;center&amp;quot; style=&amp;quot;width:30%; background:#CFA49B&amp;quot; | '''Track 1'''&amp;lt;br/&amp;gt;Horace Mann Room&lt;br /&gt;
 | align=&amp;quot;center&amp;quot; style=&amp;quot;width:30%; background:#DFC799;&amp;quot; | '''Track 2'''&amp;lt;br/&amp;gt;Deborah Sampson / Paul Thomas Room&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 10:00-10:50 || style=&amp;quot;width:30%; background:#BC857A&amp;quot; align=&amp;quot;center&amp;quot; |  &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|HTML5 Security|Ming Chow}}&lt;br /&gt;
 | style=&amp;quot;width:30%; background:#BCA57A&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|OWASP Basics 1 and 2|Robert Cheyne}}&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#9BA8CF&amp;quot; align=&amp;quot;center&amp;quot; | 11:00-11:50 || style=&amp;quot;width:30%; background:#CFA49B&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|A Crumple Zone for Service Oriented Architectures|Andrew Gronosky}}&lt;br /&gt;
 | style=&amp;quot;width:30%; background:#DFC799&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|OWASP Basics 1 and 2|Robert Cheyne}}&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 12:00-13:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;span style=&amp;quot;font-size:140%&amp;quot;&amp;gt;'''Lunch'''&amp;lt;/span&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
provided by our platinum sponsor&lt;br /&gt;
{| border=&amp;quot;1&amp;quot;&lt;br /&gt;
|[[File:SI-Banner-238x57.jpg|link=http://www.securityinnovation.com|Security Innovation]]&lt;br /&gt;
|}&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 13:00-13:50 || style=&amp;quot;width:30%; background:#BC857A&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|Hacking SAP BusinessObjects|Joshua Abraham and Will Vandevanter}}&lt;br /&gt;
 | style=&amp;quot;width:30%; background:#DFC799&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|Coffee Shop Warefare:Protecting Yourself in Dark Territory|John Carmichael}}&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 14:00-14:50 || style=&amp;quot;width:30%; background:#CFA49B&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|To Be Determined Presentation|To Be Determined}}&lt;br /&gt;
 | style=&amp;quot;width:30%; background:#DFC799&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|Url Enlargement|Dan Crowley}}&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 15:00-15:50 || style=&amp;quot;width:30%; background:#BC857A&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|Business Logic Attacks - BATs and BLBs|Paul Schofield}}&lt;br /&gt;
 | style=&amp;quot;width:30%; background:#DFC799&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|Web Applications and Data Tokenization|Kenny Smith}}&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 16:00-16:50 || style=&amp;quot;width:30%; background:#CFA49B&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|The Exploit Arms Race|Christien Rioux}}&lt;br /&gt;
 | style=&amp;quot;width:30%; background:#DFC799&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|Open SAMM|Shakeel Tufail}}&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 17:00-17:30 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:30%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;span style=&amp;quot;font-size:140%&amp;quot;&amp;gt;'''Social Time'''&amp;lt;/span&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
provided by our platinum sponsor&lt;br /&gt;
{| border=&amp;quot;1&amp;quot;&lt;br /&gt;
| [[File:boston-2010-source-277x70.jpg|link=http://www.sourceconference.com|SOURCE]]&lt;br /&gt;
|}&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 17:30-18:30 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:30%; background:#D2D2D2&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;span style=&amp;quot;font-size:140%&amp;quot;&amp;gt;'''Expert Panel'''&amp;lt;/span&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
''&lt;br /&gt;
[http://authorurl.com Josh Corman] The 451 Group, Security Analyst &amp;lt;br&amp;gt;&lt;br /&gt;
[http://authorurl.com Adriel DeSautels] NetRagard CTO &amp;lt;br&amp;gt;&lt;br /&gt;
[http://authorurl.com Justin Peavey] Omgeo, CISO &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Moderator: [http://authorurl.com   Rob Cheyne], Safelight Security Advisors, CEO''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 18:30-19:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:30%; background:#99FF99&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;span style=&amp;quot;font-size:140%&amp;quot;&amp;gt;'''Wrap Up'''&amp;lt;/span&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
{{2010_BASC:Footer_Template | Agenda}}&lt;/div&gt;</summary>
		<author><name>Mark A. Arnold</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=2010_BASC_Agenda&amp;diff=92969</id>
		<title>2010 BASC Agenda</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=2010_BASC_Agenda&amp;diff=92969"/>
				<updated>2010-11-15T05:25:50Z</updated>
		
		<summary type="html">&lt;p&gt;Mark A. Arnold: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{2010_BASC:Header_Template | Agenda}}&lt;br /&gt;
&amp;lt;!-- --------------------------------------------------------------------&lt;br /&gt;
INSTRUCTIONS FOR EDITORS:&lt;br /&gt;
&lt;br /&gt;
Updating this agenda is a 3-step process. First you must convert the existing entries to the&lt;br /&gt;
new format. You can do these one at a time or all at once. Whatever is easiest. Second, you need to&lt;br /&gt;
fill in the data for the presentation. Third, miscellaneous details should be cleaned up.&lt;br /&gt;
&lt;br /&gt;
1) To convert a presentation to the new format:&lt;br /&gt;
  - Most importantly, look at the 10:00 time slot and use it as an example.&lt;br /&gt;
  - Find the time slot you want to modify.&lt;br /&gt;
  - If it already has the Presentation Agenda Template then you are done&lt;br /&gt;
  - Copy: {{2010_BASC:Presentaton_Agenda_Template|TYPE|To Be Determined Presentation|To Be Determined}}&lt;br /&gt;
  - Delete the text that is in the time slot already. This requires great care.&lt;br /&gt;
      You probably want to delete the lines that do not begin with a &lt;br /&gt;
      pipe (|) or an open curly ({).&lt;br /&gt;
  - Paste the text you copied into that time slot.&lt;br /&gt;
  - Replace the word &amp;quot;TYPE&amp;quot; with either &amp;quot;Presentation&amp;quot; or &amp;quot;Keynote&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2) To fill in the appropriate data:&lt;br /&gt;
  - Go to http://www.owasp.org/index.php/2010_BASC_Presentations and add&lt;br /&gt;
    the presentation's abstract. If you don't have an abstract,&lt;br /&gt;
    insert &amp;quot;Presentation abstract will be available shortly.&amp;quot;&lt;br /&gt;
  - Go to http://www.owasp.org/index.php/2010_BASC_Speakers and add the speaker(s) bio.&lt;br /&gt;
    If you don't have bio information, just put the speaker's name into the page and &lt;br /&gt;
    and make their bio &amp;quot;Speaker information will be available shortly.&amp;quot;&lt;br /&gt;
    Until it presents a problem, list multiple speakers as one.&lt;br /&gt;
    For example, &amp;quot;John Boy &amp;amp; Grandpa&amp;quot;.&lt;br /&gt;
  - Find the right slot in the table.&lt;br /&gt;
  - Replace the &amp;quot;To Be Determined Presentation&amp;quot; text in the table&lt;br /&gt;
    with the presentation name __EXACTLY__ as it is on the presentation page.&lt;br /&gt;
  - Replace the &amp;quot;To Be Determined&amp;quot; text in the table&lt;br /&gt;
    with the speaker(s) name(s) __EXACTLY__ as it is on the bio page.&lt;br /&gt;
  &lt;br /&gt;
3) Clean up whatever needs cleaning up.&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------- --&amp;gt;&lt;br /&gt;
{| style=&amp;quot;width:80%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#7B8ABD; color:white&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
&amp;lt;h2&amp;gt;Saturday, November 20&amp;lt;/h2&amp;gt; &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#9BA8CF&amp;quot; align=&amp;quot;center&amp;quot; | 8:00-9:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#D2D2D2&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;div&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;font-size:140%&amp;quot;&amp;gt;'''Breakfast and Registration'''&amp;lt;/span&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
provided by our Platinum Sponsor&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
{| border=&amp;quot;1&amp;quot;&lt;br /&gt;
| [[File:Rapid7LogoSmall.png|300px|link=http://www.rapid7.com|Rapid7]]&lt;br /&gt;
|}&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 09:00-09:50 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#B0B0B0;&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;div style=&amp;quot;margin:10px;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;font-size: 140%&amp;quot;&amp;gt;'''[[2010_BASC_Presentations#Keynote|Keynote: From the Era of Vulnerabiquity to the Rugged Age]]'''&amp;lt;/span&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;font-size: 120%&amp;quot;&amp;gt;[[2010_BASC_Speakers#Josh Corman|Josh Corman]]&amp;lt;/span&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#9BA8CF&amp;quot; | || align=&amp;quot;center&amp;quot; style=&amp;quot;width:30%; background:#CFA49B&amp;quot; | '''Track 1'''&amp;lt;br/&amp;gt;Horace Mann Room&lt;br /&gt;
 | align=&amp;quot;center&amp;quot; style=&amp;quot;width:30%; background:#DFC799;&amp;quot; | '''Track 2'''&amp;lt;br/&amp;gt;Deborah Sampson / Paul Thomas Room&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 10:00-10:50 || style=&amp;quot;width:30%; background:#BC857A&amp;quot; align=&amp;quot;center&amp;quot; |  &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|HTML5 Security|Ming Chow}}&lt;br /&gt;
 | style=&amp;quot;width:30%; background:#BCA57A&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|OWASP Basics 1 and 2|Robert Cheyne}}&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#9BA8CF&amp;quot; align=&amp;quot;center&amp;quot; | 11:00-11:50 || style=&amp;quot;width:30%; background:#CFA49B&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|A Crumple Zone for Service Oriented Architectures|Andrew Gronosky}}&lt;br /&gt;
 | style=&amp;quot;width:30%; background:#DFC799&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|OWASP Basics 1 and 2|Robert Cheyne}}&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 12:00-13:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;span style=&amp;quot;font-size:140%&amp;quot;&amp;gt;'''Lunch'''&amp;lt;/span&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
provided by our platinum sponsor&lt;br /&gt;
{| border=&amp;quot;1&amp;quot;&lt;br /&gt;
|[[File:SI-Banner-238x57.jpg|link=http://www.securityinnovation.com|Security Innovation]]&lt;br /&gt;
|}&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 13:00-13:50 || style=&amp;quot;width:30%; background:#BC857A&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|Hacking SAP BusinessObjects|Joshua Abraham and Will Vandevanter}}&lt;br /&gt;
 | style=&amp;quot;width:30%; background:#DFC799&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|Coffee Shop Warefare:Protecting Yourself in Dark Territory|John Carmichael}}&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 14:00-14:50 || style=&amp;quot;width:30%; background:#CFA49B&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|To Be Determined Presentation|To Be Determined}}&lt;br /&gt;
 | style=&amp;quot;width:30%; background:#DFC799&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|Url Enlargement|Dan Crowley}}&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 15:00-15:50 || style=&amp;quot;width:30%; background:#BC857A&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|Business Logic Attacks - BATs and BLBs|Paul Schofield}}&lt;br /&gt;
 | style=&amp;quot;width:30%; background:#DFC799&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|Web Applications and Data Tokenization|Kenny Smith}}&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 16:00-16:50 || style=&amp;quot;width:30%; background:#CFA49B&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|The Exploit Arms Race|Christien Rioux}}&lt;br /&gt;
 | style=&amp;quot;width:30%; background:#DFC799&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|Open SAMM|Shakeel Tufail|Fortify}}&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 17:00-17:30 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:30%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;span style=&amp;quot;font-size:140%&amp;quot;&amp;gt;'''Social Time'''&amp;lt;/span&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
provided by our platinum sponsor&lt;br /&gt;
{| border=&amp;quot;1&amp;quot;&lt;br /&gt;
| [[File:boston-2010-source-277x70.jpg|link=http://www.sourceconference.com|SOURCE]]&lt;br /&gt;
|}&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 17:30-18:30 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:30%; background:#D2D2D2&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;span style=&amp;quot;font-size:140%&amp;quot;&amp;gt;'''Expert Panel'''&amp;lt;/span&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
''&lt;br /&gt;
[http://authorurl.com Josh Corman] The 451 Group, Security Analyst &amp;lt;br&amp;gt;&lt;br /&gt;
[http://authorurl.com Adriel DeSautels] NetRagard CTO &amp;lt;br&amp;gt;&lt;br /&gt;
[http://authorurl.com Justin Peavey] Omgeo, CISO &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Moderator: [http://authorurl.com   Rob Cheyne], Safelight Security Advisors, CEO''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 18:30-19:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:30%; background:#99FF99&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;span style=&amp;quot;font-size:140%&amp;quot;&amp;gt;'''Wrap Up'''&amp;lt;/span&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
{{2010_BASC:Footer_Template | Agenda}}&lt;/div&gt;</summary>
		<author><name>Mark A. Arnold</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=2010_BASC_Agenda&amp;diff=92968</id>
		<title>2010 BASC Agenda</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=2010_BASC_Agenda&amp;diff=92968"/>
				<updated>2010-11-15T04:59:30Z</updated>
		
		<summary type="html">&lt;p&gt;Mark A. Arnold: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{2010_BASC:Header_Template | Agenda}}&lt;br /&gt;
&amp;lt;!-- --------------------------------------------------------------------&lt;br /&gt;
INSTRUCTIONS FOR EDITORS:&lt;br /&gt;
&lt;br /&gt;
Updating this agenda is a 3-step process. First you must convert the existing entries to the&lt;br /&gt;
new format. You can do these one at a time or all at once. Whatever is easiest. Second, you need to&lt;br /&gt;
fill in the data for the presentation. Third, miscellaneous details should be cleaned up.&lt;br /&gt;
&lt;br /&gt;
1) To convert a presentation to the new format:&lt;br /&gt;
  - Most importantly, look at the 10:00 time slot and use it as an example.&lt;br /&gt;
  - Find the time slot you want to modify.&lt;br /&gt;
  - If it already has the Presentation Agenda Template then you are done&lt;br /&gt;
  - Copy: {{2010_BASC:Presentaton_Agenda_Template|TYPE|To Be Determined Presentation|To Be Determined}}&lt;br /&gt;
  - Delete the text that is in the time slot already. This requires great care.&lt;br /&gt;
      You probably want to delete the lines that do not begin with a &lt;br /&gt;
      pipe (|) or an open curly ({).&lt;br /&gt;
  - Paste the text you copied into that time slot.&lt;br /&gt;
  - Replace the word &amp;quot;TYPE&amp;quot; with either &amp;quot;Presentation&amp;quot; or &amp;quot;Keynote&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2) To fill in the appropriate data:&lt;br /&gt;
  - Go to http://www.owasp.org/index.php/2010_BASC_Presentations and add&lt;br /&gt;
    the presentation's abstract. If you don't have an abstract,&lt;br /&gt;
    insert &amp;quot;Presentation abstract will be available shortly.&amp;quot;&lt;br /&gt;
  - Go to http://www.owasp.org/index.php/2010_BASC_Speakers and add the speaker(s) bio.&lt;br /&gt;
    If you don't have bio information, just put the speaker's name into the page and &lt;br /&gt;
    and make their bio &amp;quot;Speaker information will be available shortly.&amp;quot;&lt;br /&gt;
    Until it presents a problem, list multiple speakers as one.&lt;br /&gt;
    For example, &amp;quot;John Boy &amp;amp; Grandpa&amp;quot;.&lt;br /&gt;
  - Find the right slot in the table.&lt;br /&gt;
  - Replace the &amp;quot;To Be Determined Presentation&amp;quot; text in the table&lt;br /&gt;
    with the presentation name __EXACTLY__ as it is on the presentation page.&lt;br /&gt;
  - Replace the &amp;quot;To Be Determined&amp;quot; text in the table&lt;br /&gt;
    with the speaker(s) name(s) __EXACTLY__ as it is on the bio page.&lt;br /&gt;
  &lt;br /&gt;
3) Clean up whatever needs cleaning up.&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------- --&amp;gt;&lt;br /&gt;
{| style=&amp;quot;width:80%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#7B8ABD; color:white&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
&amp;lt;h2&amp;gt;Saturday, November 20&amp;lt;/h2&amp;gt; &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#9BA8CF&amp;quot; align=&amp;quot;center&amp;quot; | 8:00-9:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#D2D2D2&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;div&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;font-size:140%&amp;quot;&amp;gt;'''Breakfast and Registration'''&amp;lt;/span&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
provided by our Platinum Sponsor&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
{| border=&amp;quot;1&amp;quot;&lt;br /&gt;
| [[File:Rapid7LogoSmall.png|300px|link=http://www.rapid7.com|Rapid7]]&lt;br /&gt;
|}&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 09:00-09:50 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#B0B0B0;&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;div style=&amp;quot;margin:10px;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;font-size: 140%&amp;quot;&amp;gt;'''[[2010_BASC_Presentations#Keynote|Keynote: From the Era of Vulnerabiquity to the Rugged Age]]'''&amp;lt;/span&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;font-size: 120%&amp;quot;&amp;gt;[[2010_BASC_Speakers#Josh Corman|Josh Corman]]&amp;lt;/span&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#9BA8CF&amp;quot; | || align=&amp;quot;center&amp;quot; style=&amp;quot;width:30%; background:#CFA49B&amp;quot; | '''Track 1'''&amp;lt;br/&amp;gt;Horace Mann Room&lt;br /&gt;
 | align=&amp;quot;center&amp;quot; style=&amp;quot;width:30%; background:#DFC799;&amp;quot; | '''Track 2'''&amp;lt;br/&amp;gt;Deborah Sampson / Paul Thomas Room&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 10:00-10:50 || style=&amp;quot;width:30%; background:#BC857A&amp;quot; align=&amp;quot;center&amp;quot; |  &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|HTML5 Security|Ming Chow}}&lt;br /&gt;
 | style=&amp;quot;width:30%; background:#BCA57A&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|OWASP Basics 1 and 2|Robert Cheyne}}&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#9BA8CF&amp;quot; align=&amp;quot;center&amp;quot; | 11:00-11:50 || style=&amp;quot;width:30%; background:#CFA49B&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|A Crumple Zone for Service Oriented Architectures|Andrew Gronosky}}&lt;br /&gt;
 | style=&amp;quot;width:30%; background:#DFC799&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|OWASP Basics 1 and 2|Robert Cheyne}}&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 12:00-13:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;span style=&amp;quot;font-size:140%&amp;quot;&amp;gt;'''Lunch'''&amp;lt;/span&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
provided by our platinum sponsor&lt;br /&gt;
{| border=&amp;quot;1&amp;quot;&lt;br /&gt;
|[[File:SI-Banner-238x57.jpg|link=http://www.securityinnovation.com|Security Innovation]]&lt;br /&gt;
|}&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 13:00-13:50 || style=&amp;quot;width:30%; background:#BC857A&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|Hacking SAP BusinessObjects|Joshua Abraham and Will Vandevanter}}&lt;br /&gt;
 | style=&amp;quot;width:30%; background:#DFC799&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|Coffee Shop Warefare:Protecting Yourself in Dark Territory|John Carmichael}}&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 14:00-14:50 || style=&amp;quot;width:30%; background:#CFA49B&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|To Be Determined Presentation|To Be Determined}}&lt;br /&gt;
 | style=&amp;quot;width:30%; background:#DFC799&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|Url Enlargement|Dan Crowley}}&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 15:00-15:50 || style=&amp;quot;width:30%; background:#BC857A&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|Business Logic Attacks - BATs and BLBs|Paul Schofield}}&lt;br /&gt;
 | style=&amp;quot;width:30%; background:#DFC799&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|Web Applications and Data Tokenization|Kenny Smith}}&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 16:00-16:50 || style=&amp;quot;width:30%; background:#CFA49B&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|The Exploit Arms Race|Christien Rioux}}&lt;br /&gt;
 | style=&amp;quot;width:30%; background:#DFC799&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|Open SAMM|Shakeel Tufail}}&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 17:00-17:30 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:30%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;span style=&amp;quot;font-size:140%&amp;quot;&amp;gt;'''Social Time'''&amp;lt;/span&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
provided by our platinum sponsor&lt;br /&gt;
{| border=&amp;quot;1&amp;quot;&lt;br /&gt;
| [[File:boston-2010-source-277x70.jpg|link=http://www.sourceconference.com|SOURCE]]&lt;br /&gt;
|}&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 17:30-18:30 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:30%; background:#D2D2D2&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;span style=&amp;quot;font-size:140%&amp;quot;&amp;gt;'''Expert Panel'''&amp;lt;/span&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
''&lt;br /&gt;
[http://authorurl.com Josh Corman] The 451 Group, Security Analyst &amp;lt;br&amp;gt;&lt;br /&gt;
[http://authorurl.com Adriel DeSautels] NetRagard CTO &amp;lt;br&amp;gt;&lt;br /&gt;
[http://authorurl.com Justin Peavey] Omgeo, CISO &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Moderator: [http://authorurl.com   Rob Cheyne], Safelight Security Advisors, CEO''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 18:30-19:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:30%; background:#99FF99&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;span style=&amp;quot;font-size:140%&amp;quot;&amp;gt;'''Wrap Up'''&amp;lt;/span&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
{{2010_BASC:Footer_Template | Agenda}}&lt;/div&gt;</summary>
		<author><name>Mark A. Arnold</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=2010_BASC_Agenda&amp;diff=92933</id>
		<title>2010 BASC Agenda</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=2010_BASC_Agenda&amp;diff=92933"/>
				<updated>2010-11-14T05:12:28Z</updated>
		
		<summary type="html">&lt;p&gt;Mark A. Arnold: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{2010_BASC:Header_Template | Agenda}}&lt;br /&gt;
{{2010_BASC:WIP_Template}}&lt;br /&gt;
&amp;lt;!-- --------------------------------------------------------------------&lt;br /&gt;
INSTRUCTIONS FOR EDITORS:&lt;br /&gt;
&lt;br /&gt;
Updating this agenda is a 3-step process. First you must convert the existing entries to the&lt;br /&gt;
new format. You can do these one at a time or all at once. Whatever is easiest. Second, you need to&lt;br /&gt;
fill in the data for the presentation. Third, miscellaneous details should be cleaned up.&lt;br /&gt;
&lt;br /&gt;
1) To convert a presentation to the new format:&lt;br /&gt;
  - Most importantly, look at the 10:00 time slot and use it as an example.&lt;br /&gt;
  - Find the time slot you want to modify.&lt;br /&gt;
  - If it already has the Presentation Agenda Template then you are done&lt;br /&gt;
  - Copy: {{2010_BASC:Presentaton_Agenda_Template|TYPE|To Be Determined Presentation|To Be Determined}}&lt;br /&gt;
  - Delete the text that is in the time slot already. This requires great care.&lt;br /&gt;
      You probably want to delete the lines that do not begin with a &lt;br /&gt;
      pipe (|) or an open curly ({).&lt;br /&gt;
  - Paste the text you copied into that time slot.&lt;br /&gt;
  - Replace the word &amp;quot;TYPE&amp;quot; with either &amp;quot;Presentation&amp;quot; or &amp;quot;Keynote&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2) To fill in the appropriate data:&lt;br /&gt;
  - Go to http://www.owasp.org/index.php/2010_BASC_Presentations and add&lt;br /&gt;
    the presentation's abstract. If you don't have an abstract,&lt;br /&gt;
    insert &amp;quot;Presentation abstract will be available shortly.&amp;quot;&lt;br /&gt;
  - Go to http://www.owasp.org/index.php/2010_BASC_Speakers and add the speaker(s) bio.&lt;br /&gt;
    If you don't have bio information, just put the speaker's name into the page and &lt;br /&gt;
    and make their bio &amp;quot;Speaker information will be available shortly.&amp;quot;&lt;br /&gt;
    Until it presents a problem, list multiple speakers as one.&lt;br /&gt;
    For example, &amp;quot;John Boy &amp;amp; Grandpa&amp;quot;.&lt;br /&gt;
  - Find the right slot in the table.&lt;br /&gt;
  - Replace the &amp;quot;To Be Determined Presentation&amp;quot; text in the table&lt;br /&gt;
    with the presentation name __EXACTLY__ as it is on the presentation page.&lt;br /&gt;
  - Replace the &amp;quot;To Be Determined&amp;quot; text in the table&lt;br /&gt;
    with the speaker(s) name(s) __EXACTLY__ as it is on the bio page.&lt;br /&gt;
  &lt;br /&gt;
3) Clean up whatever needs cleaning up.&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------- --&amp;gt;&lt;br /&gt;
{| style=&amp;quot;width:80%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#7B8ABD; color:white&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
&amp;lt;h2&amp;gt;Saturday, November 20&amp;lt;/h2&amp;gt; &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#9BA8CF&amp;quot; align=&amp;quot;center&amp;quot; | 8:00-9:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#D2D2D2&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size: 120%;&amp;quot;&amp;gt;&lt;br /&gt;
'''Breakfast and Registration'''&amp;lt;br/&amp;gt;&lt;br /&gt;
provided by our Platinum Sponsor:&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
{| border=&amp;quot;1&amp;quot;&lt;br /&gt;
| [[File:Rapid7LogoSmall.png|300px|link=http://www.rapid7.com|Rapid7]]&lt;br /&gt;
|}&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 09:00-09:50 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#B0B0B0;&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Keynote|To Be Determined Presentation|Josh Corman}}&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#9BA8CF&amp;quot; | || align=&amp;quot;center&amp;quot; style=&amp;quot;width:30%; background:#CFA49B&amp;quot; | '''Track 1'''&amp;lt;br/&amp;gt;Horace Mann Room&lt;br /&gt;
 | align=&amp;quot;center&amp;quot; style=&amp;quot;width:30%; background:#DFC799;&amp;quot; | '''Track 2'''&amp;lt;br/&amp;gt;Deborah Sampson / Paul Thomas Room&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 10:00-10:50 || style=&amp;quot;width:30%; background:#BC857A&amp;quot; align=&amp;quot;center&amp;quot; |  &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|HTML5 Security|Ming Chow}}&lt;br /&gt;
 | style=&amp;quot;width:30%; background:#BCA57A&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|OWASP Basics 1 and 2|Robert Cheyne}}&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#9BA8CF&amp;quot; align=&amp;quot;center&amp;quot; | 11:00-11:50 || style=&amp;quot;width:30%; background:#CFA49B&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|A Crumple Zone for Service Oriented Architectures|Andrew Gronosky}}&lt;br /&gt;
 | style=&amp;quot;width:30%; background:#DFC799&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|OWASP Basics 1 and 2|Robert Cheyne}}&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 12:00-13:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
'''Lunch provided by our platinum sponsor'''&lt;br /&gt;
{| border=&amp;quot;1&amp;quot;&lt;br /&gt;
|[[File:SI-Banner-238x57.jpg|link=http://www.securityinnovation.com|Security Innovation]]&lt;br /&gt;
|}&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 13:00-13:50 || style=&amp;quot;width:30%; background:#BC857A&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|Hacking SAP BusinessObjects|Joshua Abraham and Will Vandevanter}}&lt;br /&gt;
 | style=&amp;quot;width:30%; background:#DFC799&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|Coffee Shop Warefare:Protecting Yourself in Dark Territory|John Carmichael}}&lt;br /&gt;
|-&lt;br /&gt;
 &lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 14:00-14:50 || style=&amp;quot;width:30%; background:#CFA49B&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|The Exploit Arms Race|Christien Rioux}}&lt;br /&gt;
 | style=&amp;quot;width:30%; background:#DFC799&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|Url Enlargement|Dan Crowley}}&lt;br /&gt;
|-&lt;br /&gt;
 &lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 15:00-15:50 || style=&amp;quot;width:30%; background:#BC857A&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|Business Logic Attacks - BATs and BLBs|Paul Schofield}}&lt;br /&gt;
 | style=&amp;quot;width:30%; background:#DFC799&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|Web Applications and Data Tokenization|Kenny Smith}}&lt;br /&gt;
|-&lt;br /&gt;
 &lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 16:00-16:50 || style=&amp;quot;width:30%; background:#CFA49B&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|To Be Determined Presentation|To Be Determined}}&lt;br /&gt;
 | style=&amp;quot;width:30%; background:#DFC799&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|Open SAMM|Shakeel Tufail}}&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 17:00-17:30 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:30%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
'''Social Time provided by our platinum sponsor'''&lt;br /&gt;
{| border=&amp;quot;1&amp;quot;&lt;br /&gt;
| [[File:boston-2010-source-277x70.jpg|link=http://www.sourceconference.com|SOURCE]]&lt;br /&gt;
|}&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 17:30-18:30 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:30%; background:#D2D2D2&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
'''Expert Panel:'''&amp;lt;br&amp;gt;&lt;br /&gt;
''[http://authorurl.com Presenter Name] Company &amp;amp; Title, &amp;lt;br&amp;gt;&lt;br /&gt;
[http://authorurl.com Presenter Name] Company &amp;amp; Title, &amp;lt;br&amp;gt;&lt;br /&gt;
[http://authorurl.com Presenter Name] Company &amp;amp; Title, &amp;lt;br&amp;gt;&lt;br /&gt;
[http://authorurl.com Presenter Name] Company &amp;amp; Title, &amp;lt;br&amp;gt;&lt;br /&gt;
[http://authorurl.com Presenter Name] Company &amp;amp; Title, &amp;lt;br&amp;gt;&lt;br /&gt;
[http://authorurl.com Presenter Name] Company &amp;amp; Title, &amp;lt;br&amp;gt;&lt;br /&gt;
Moderator: [http://authorurl.com   Moderator Name]''&amp;lt;br&amp;gt;&lt;br /&gt;
[http://video.google.com/ VIDEO] / [http://owasp.org SLIDES]&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 18:30-19:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:30%; background:#99FF99&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
'''Wrap Up'''&amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
{{2010_BASC:WIP_Template}}&lt;br /&gt;
{{2010_BASC:Footer_Template | Agenda}}&lt;/div&gt;</summary>
		<author><name>Mark A. Arnold</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=2010_BASC_Agenda&amp;diff=92932</id>
		<title>2010 BASC Agenda</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=2010_BASC_Agenda&amp;diff=92932"/>
				<updated>2010-11-14T05:09:01Z</updated>
		
		<summary type="html">&lt;p&gt;Mark A. Arnold: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{2010_BASC:Header_Template | Agenda}}&lt;br /&gt;
{{2010_BASC:WIP_Template}}&lt;br /&gt;
&amp;lt;!-- --------------------------------------------------------------------&lt;br /&gt;
INSTRUCTIONS FOR EDITORS:&lt;br /&gt;
&lt;br /&gt;
Updating this agenda is a 3-step process. First you must convert the existing entries to the&lt;br /&gt;
new format. You can do these one at a time or all at once. Whatever is easiest. Second, you need to&lt;br /&gt;
fill in the data for the presentation. Third, miscellaneous details should be cleaned up.&lt;br /&gt;
&lt;br /&gt;
1) To convert a presentation to the new format:&lt;br /&gt;
  - Most importantly, look at the 10:00 time slot and use it as an example.&lt;br /&gt;
  - Find the time slot you want to modify.&lt;br /&gt;
  - If it already has the Presentation Agenda Template then you are done&lt;br /&gt;
  - Copy: {{2010_BASC:Presentaton_Agenda_Template|TYPE|To Be Determined Presentation|To Be Determined}}&lt;br /&gt;
  - Delete the text that is in the time slot already. This requires great care.&lt;br /&gt;
      You probably want to delete the lines that do not begin with a &lt;br /&gt;
      pipe (|) or an open curly ({).&lt;br /&gt;
  - Paste the text you copied into that time slot.&lt;br /&gt;
  - Replace the word &amp;quot;TYPE&amp;quot; with either &amp;quot;Presentation&amp;quot; or &amp;quot;Keynote&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2) To fill in the appropriate data:&lt;br /&gt;
  - Go to http://www.owasp.org/index.php/2010_BASC_Presentations and add&lt;br /&gt;
    the presentation's abstract. If you don't have an abstract,&lt;br /&gt;
    insert &amp;quot;Presentation abstract will be available shortly.&amp;quot;&lt;br /&gt;
  - Go to http://www.owasp.org/index.php/2010_BASC_Speakers and add the speaker(s) bio.&lt;br /&gt;
    If you don't have bio information, just put the speaker's name into the page and &lt;br /&gt;
    and make their bio &amp;quot;Speaker information will be available shortly.&amp;quot;&lt;br /&gt;
    Until it presents a problem, list multiple speakers as one.&lt;br /&gt;
    For example, &amp;quot;John Boy &amp;amp; Grandpa&amp;quot;.&lt;br /&gt;
  - Find the right slot in the table.&lt;br /&gt;
  - Replace the &amp;quot;To Be Determined Presentation&amp;quot; text in the table&lt;br /&gt;
    with the presentation name __EXACTLY__ as it is on the presentation page.&lt;br /&gt;
  - Replace the &amp;quot;To Be Determined&amp;quot; text in the table&lt;br /&gt;
    with the speaker(s) name(s) __EXACTLY__ as it is on the bio page.&lt;br /&gt;
  &lt;br /&gt;
3) Clean up whatever needs cleaning up.&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------- --&amp;gt;&lt;br /&gt;
{| style=&amp;quot;width:80%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#7B8ABD; color:white&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
&amp;lt;h2&amp;gt;Saturday, November 20&amp;lt;/h2&amp;gt; &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#9BA8CF&amp;quot; align=&amp;quot;center&amp;quot; | 8:00-9:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#D2D2D2&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size: 120%;&amp;quot;&amp;gt;&lt;br /&gt;
'''Breakfast and Registration'''&amp;lt;br/&amp;gt;&lt;br /&gt;
provided by our Platinum Sponsor:&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
{| border=&amp;quot;1&amp;quot;&lt;br /&gt;
| [[File:Rapid7LogoSmall.png|300px|link=http://www.rapid7.com|Rapid7]]&lt;br /&gt;
|}&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 09:00-09:50 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#B0B0B0;&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Keynote|To Be Determined Presentation|Josh Corman}}&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#9BA8CF&amp;quot; | || align=&amp;quot;center&amp;quot; style=&amp;quot;width:30%; background:#CFA49B&amp;quot; | '''Track 1'''&amp;lt;br/&amp;gt;Horace Mann Room&lt;br /&gt;
 | align=&amp;quot;center&amp;quot; style=&amp;quot;width:30%; background:#DFC799;&amp;quot; | '''Track 2'''&amp;lt;br/&amp;gt;Deborah Sampson / Paul Thomas Room&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 10:00-10:50 || style=&amp;quot;width:30%; background:#BC857A&amp;quot; align=&amp;quot;center&amp;quot; |  &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|HTML5 Security|Ming Chow}}&lt;br /&gt;
 | style=&amp;quot;width:30%; background:#BCA57A&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|OWASP Basics 1 and 2|Robert Cheyne}}&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#9BA8CF&amp;quot; align=&amp;quot;center&amp;quot; | 11:00-11:50 || style=&amp;quot;width:30%; background:#CFA49B&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|A Crumple Zone for Service Oriented Architectures|Andrew Gronosky}}&lt;br /&gt;
 | style=&amp;quot;width:30%; background:#DFC799&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|OWASP Basics 1 and 2|Robert Cheyne}}&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 12:00-13:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
'''Lunch provided by our platinum sponsor'''&lt;br /&gt;
{| border=&amp;quot;1&amp;quot;&lt;br /&gt;
|[[File:SI-Banner-238x57.jpg|link=http://www.securityinnovation.com|Security Innovation]]&lt;br /&gt;
|}&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 13:00-13:50 || style=&amp;quot;width:30%; background:#BC857A&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|Hacking SAP BusinessObjects|Joshua Abraham and Will Vandevanter}}&lt;br /&gt;
 | style=&amp;quot;width:30%; background:#DFC799&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|Coffee Shop Warefare:Protecting Yourself in Dark Territory|John Carmichael}}&lt;br /&gt;
|-&lt;br /&gt;
 &lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 14:00-14:50 || style=&amp;quot;width:30%; background:#CFA49B&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|The Exploit Arms Race|Christien Rioux}}&lt;br /&gt;
 | style=&amp;quot;width:30%; background:#DFC799&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|Url Enlargement|Dan Crowley}}&lt;br /&gt;
|-&lt;br /&gt;
 &lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 15:00-15:50 || style=&amp;quot;width:30%; background:#BC857A&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|Business Logic Attacks - BATs and BLBs|Paul Schofield}}&lt;br /&gt;
 | style=&amp;quot;width:30%; background:#DFC799&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|Coffee Shop Warefare:Protecting Yourself in Dark Territory|John Carmichael}}&lt;br /&gt;
|-&lt;br /&gt;
 &lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 16:00-16:50 || style=&amp;quot;width:30%; background:#CFA49B&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|To Be Determined Presentation|To Be Determined}}&lt;br /&gt;
 | style=&amp;quot;width:30%; background:#DFC799&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|Open SAMM|Shakeel Tufail}}&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 17:00-17:30 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:30%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
'''Social Time provided by our platinum sponsor'''&lt;br /&gt;
{| border=&amp;quot;1&amp;quot;&lt;br /&gt;
| [[File:boston-2010-source-277x70.jpg|link=http://www.sourceconference.com|SOURCE]]&lt;br /&gt;
|}&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 17:30-18:30 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:30%; background:#D2D2D2&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
'''Expert Panel:'''&amp;lt;br&amp;gt;&lt;br /&gt;
''[http://authorurl.com Presenter Name] Company &amp;amp; Title, &amp;lt;br&amp;gt;&lt;br /&gt;
[http://authorurl.com Presenter Name] Company &amp;amp; Title, &amp;lt;br&amp;gt;&lt;br /&gt;
[http://authorurl.com Presenter Name] Company &amp;amp; Title, &amp;lt;br&amp;gt;&lt;br /&gt;
[http://authorurl.com Presenter Name] Company &amp;amp; Title, &amp;lt;br&amp;gt;&lt;br /&gt;
[http://authorurl.com Presenter Name] Company &amp;amp; Title, &amp;lt;br&amp;gt;&lt;br /&gt;
[http://authorurl.com Presenter Name] Company &amp;amp; Title, &amp;lt;br&amp;gt;&lt;br /&gt;
Moderator: [http://authorurl.com   Moderator Name]''&amp;lt;br&amp;gt;&lt;br /&gt;
[http://video.google.com/ VIDEO] / [http://owasp.org SLIDES]&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 18:30-19:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:30%; background:#99FF99&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
'''Wrap Up'''&amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
{{2010_BASC:WIP_Template}}&lt;br /&gt;
{{2010_BASC:Footer_Template | Agenda}}&lt;/div&gt;</summary>
		<author><name>Mark A. Arnold</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=2010_BASC_Agenda&amp;diff=92931</id>
		<title>2010 BASC Agenda</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=2010_BASC_Agenda&amp;diff=92931"/>
				<updated>2010-11-14T04:40:46Z</updated>
		
		<summary type="html">&lt;p&gt;Mark A. Arnold: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{2010_BASC:Header_Template | Agenda}}&lt;br /&gt;
{{2010_BASC:WIP_Template}}&lt;br /&gt;
&amp;lt;!-- --------------------------------------------------------------------&lt;br /&gt;
INSTRUCTIONS FOR EDITORS:&lt;br /&gt;
&lt;br /&gt;
Updating this agenda is a 3-step process. First you must convert the existing entries to the&lt;br /&gt;
new format. You can do these one at a time or all at once. Whatever is easiest. Second, you need to&lt;br /&gt;
fill in the data for the presentation. Third, miscellaneous details should be cleaned up.&lt;br /&gt;
&lt;br /&gt;
1) To convert a presentation to the new format:&lt;br /&gt;
  - Most importantly, look at the 10:00 time slot and use it as an example.&lt;br /&gt;
  - Find the time slot you want to modify.&lt;br /&gt;
  - If it already has the Presentation Agenda Template then you are done&lt;br /&gt;
  - Copy: {{2010_BASC:Presentaton_Agenda_Template|TYPE|To Be Determined Presentation|To Be Determined}}&lt;br /&gt;
  - Delete the text that is in the time slot already. This requires great care.&lt;br /&gt;
      You probably want to delete the lines that do not begin with a &lt;br /&gt;
      pipe (|) or an open curly ({).&lt;br /&gt;
  - Paste the text you copied into that time slot.&lt;br /&gt;
  - Replace the word &amp;quot;TYPE&amp;quot; with either &amp;quot;Presentation&amp;quot; or &amp;quot;Keynote&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2) To fill in the appropriate data:&lt;br /&gt;
  - Go to http://www.owasp.org/index.php/2010_BASC_Presentations and add&lt;br /&gt;
    the presentation's abstract. If you don't have an abstract,&lt;br /&gt;
    insert &amp;quot;Presentation abstract will be available shortly.&amp;quot;&lt;br /&gt;
  - Go to http://www.owasp.org/index.php/2010_BASC_Speakers and add the speaker(s) bio.&lt;br /&gt;
    If you don't have bio information, just put the speaker's name into the page and &lt;br /&gt;
    and make their bio &amp;quot;Speaker information will be available shortly.&amp;quot;&lt;br /&gt;
    Until it presents a problem, list multiple speakers as one.&lt;br /&gt;
    For example, &amp;quot;John Boy &amp;amp; Grandpa&amp;quot;.&lt;br /&gt;
  - Find the right slot in the table.&lt;br /&gt;
  - Replace the &amp;quot;To Be Determined Presentation&amp;quot; text in the table&lt;br /&gt;
    with the presentation name __EXACTLY__ as it is on the presentation page.&lt;br /&gt;
  - Replace the &amp;quot;To Be Determined&amp;quot; text in the table&lt;br /&gt;
    with the speaker(s) name(s) __EXACTLY__ as it is on the bio page.&lt;br /&gt;
  &lt;br /&gt;
3) Clean up whatever needs cleaning up.&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------- --&amp;gt;&lt;br /&gt;
{| style=&amp;quot;width:80%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#7B8ABD; color:white&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
&amp;lt;h2&amp;gt;Saturday, November 20&amp;lt;/h2&amp;gt; &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#9BA8CF&amp;quot; align=&amp;quot;center&amp;quot; | 8:00-9:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#D2D2D2&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size: 120%;&amp;quot;&amp;gt;&lt;br /&gt;
'''Breakfast and Registration'''&amp;lt;br/&amp;gt;&lt;br /&gt;
provided by our Platinum Sponsor:&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
{| border=&amp;quot;1&amp;quot;&lt;br /&gt;
| [[File:Rapid7LogoSmall.png|300px|link=http://www.rapid7.com|Rapid7]]&lt;br /&gt;
|}&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 09:00-09:50 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#B0B0B0;&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Keynote|To Be Determined Presentation|Josh Corman}}&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#9BA8CF&amp;quot; | || align=&amp;quot;center&amp;quot; style=&amp;quot;width:30%; background:#CFA49B&amp;quot; | '''Track 1'''&amp;lt;br/&amp;gt;Horace Mann Room&lt;br /&gt;
 | align=&amp;quot;center&amp;quot; style=&amp;quot;width:30%; background:#DFC799;&amp;quot; | '''Track 2'''&amp;lt;br/&amp;gt;Deborah Sampson / Paul Thomas Room&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 10:00-10:50 || style=&amp;quot;width:30%; background:#BC857A&amp;quot; align=&amp;quot;center&amp;quot; |  &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|HTML5 Security|Ming Chow}}&lt;br /&gt;
 | style=&amp;quot;width:30%; background:#BCA57A&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|OWASP Basics 1 and 2|Robert Cheyne}}&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#9BA8CF&amp;quot; align=&amp;quot;center&amp;quot; | 11:00-11:50 || style=&amp;quot;width:30%; background:#CFA49B&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|A Crumple Zone for Service Oriented Architectures|Andrew Gronosky}}&lt;br /&gt;
 | style=&amp;quot;width:30%; background:#DFC799&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|OWASP Basics 1 and 2|Robert Cheyne}}&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 12:00-13:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
'''Lunch provided by our platinum sponsor'''&lt;br /&gt;
{| border=&amp;quot;1&amp;quot;&lt;br /&gt;
|[[File:SI-Banner-238x57.jpg|link=http://www.securityinnovation.com|Security Innovation]]&lt;br /&gt;
|}&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 13:00-13:50 || style=&amp;quot;width:30%; background:#BC857A&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|Hacking SAP BusinessObjects|Joshua Abraham and Will Vandevanter}}&lt;br /&gt;
 | style=&amp;quot;width:30%; background:#DFC799&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|Coffee Shop Warefare:Protecting Yourself in Dark Territory|John Carmichael}}&lt;br /&gt;
|-&lt;br /&gt;
 &lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 14:00-14:50 || style=&amp;quot;width:30%; background:#CFA49B&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|The Exploit Arms Race|Christien Rioux}}&lt;br /&gt;
 | style=&amp;quot;width:30%; background:#DFC799&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|Url Enlargement|Dan Crowley}}&lt;br /&gt;
|-&lt;br /&gt;
 &lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 15:00-15:50 || style=&amp;quot;width:30%; background:#BC857A&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|Business Logic Attacks - BATs and BLBs|Paul Schofield}}&lt;br /&gt;
 | style=&amp;quot;width:30%; background:#DFC799&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|Coffee Shop Warefare:Protecting Yourself in Dark Territory|John Carmichael}}&lt;br /&gt;
|-&lt;br /&gt;
 &lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 16:00-16:50 || style=&amp;quot;width:30%; background:#CFA49B&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|Business Logic Attacks - BATs and BLBs|Paul Schofield}}&lt;br /&gt;
 | style=&amp;quot;width:30%; background:#DFC799&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|Web Applications and Data Tokenization|Kenny Smith}}&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 17:00-17:30 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:30%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
'''Social Time provided by our platinum sponsor'''&lt;br /&gt;
{| border=&amp;quot;1&amp;quot;&lt;br /&gt;
| [[File:boston-2010-source-277x70.jpg|link=http://www.sourceconference.com|SOURCE]]&lt;br /&gt;
|}&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 17:30-18:30 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:30%; background:#D2D2D2&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
'''Expert Panel:'''&amp;lt;br&amp;gt;&lt;br /&gt;
''[http://authorurl.com Presenter Name] Company &amp;amp; Title, &amp;lt;br&amp;gt;&lt;br /&gt;
[http://authorurl.com Presenter Name] Company &amp;amp; Title, &amp;lt;br&amp;gt;&lt;br /&gt;
[http://authorurl.com Presenter Name] Company &amp;amp; Title, &amp;lt;br&amp;gt;&lt;br /&gt;
[http://authorurl.com Presenter Name] Company &amp;amp; Title, &amp;lt;br&amp;gt;&lt;br /&gt;
[http://authorurl.com Presenter Name] Company &amp;amp; Title, &amp;lt;br&amp;gt;&lt;br /&gt;
[http://authorurl.com Presenter Name] Company &amp;amp; Title, &amp;lt;br&amp;gt;&lt;br /&gt;
Moderator: [http://authorurl.com   Moderator Name]''&amp;lt;br&amp;gt;&lt;br /&gt;
[http://video.google.com/ VIDEO] / [http://owasp.org SLIDES]&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 18:30-19:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:30%; background:#99FF99&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
'''Wrap Up'''&amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
{{2010_BASC:WIP_Template}}&lt;br /&gt;
{{2010_BASC:Footer_Template | Agenda}}&lt;/div&gt;</summary>
		<author><name>Mark A. Arnold</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=2010_BASC_Agenda&amp;diff=92930</id>
		<title>2010 BASC Agenda</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=2010_BASC_Agenda&amp;diff=92930"/>
				<updated>2010-11-14T04:13:28Z</updated>
		
		<summary type="html">&lt;p&gt;Mark A. Arnold: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{2010_BASC:Header_Template | Agenda}}&lt;br /&gt;
{{2010_BASC:WIP_Template}}&lt;br /&gt;
&amp;lt;!-- --------------------------------------------------------------------&lt;br /&gt;
INSTRUCTIONS FOR EDITORS:&lt;br /&gt;
&lt;br /&gt;
Updating this agenda is a 3-step process. First you must convert the existing entries to the&lt;br /&gt;
new format. You can do these one at a time or all at once. Whatever is easiest. Second, you need to&lt;br /&gt;
fill in the data for the presentation. Third, miscellaneous details should be cleaned up.&lt;br /&gt;
&lt;br /&gt;
1) To convert a presentation to the new format:&lt;br /&gt;
  - Most importantly, look at the 10:00 time slot and use it as an example.&lt;br /&gt;
  - Find the time slot you want to modify.&lt;br /&gt;
  - If it already has the Presentation Agenda Template then you are done&lt;br /&gt;
  - Copy: {{2010_BASC:Presentaton_Agenda_Template|TYPE|To Be Determined Presentation|To Be Determined}}&lt;br /&gt;
  - Delete the text that is in the time slot already. This requires great care.&lt;br /&gt;
      You probably want to delete the lines that do not begin with a &lt;br /&gt;
      pipe (|) or an open curly ({).&lt;br /&gt;
  - Paste the text you copied into that time slot.&lt;br /&gt;
  - Replace the word &amp;quot;TYPE&amp;quot; with either &amp;quot;Presentation&amp;quot; or &amp;quot;Keynote&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2) To fill in the appropriate data:&lt;br /&gt;
  - Go to http://www.owasp.org/index.php/2010_BASC_Presentations and add&lt;br /&gt;
    the presentation's abstract. If you don't have an abstract,&lt;br /&gt;
    insert &amp;quot;Presentation abstract will be available shortly.&amp;quot;&lt;br /&gt;
  - Go to http://www.owasp.org/index.php/2010_BASC_Speakers and add the speaker(s) bio.&lt;br /&gt;
    If you don't have bio information, just put the speaker's name into the page and &lt;br /&gt;
    and make their bio &amp;quot;Speaker information will be available shortly.&amp;quot;&lt;br /&gt;
    Until it presents a problem, list multiple speakers as one.&lt;br /&gt;
    For example, &amp;quot;John Boy &amp;amp; Grandpa&amp;quot;.&lt;br /&gt;
  - Find the right slot in the table.&lt;br /&gt;
  - Replace the &amp;quot;To Be Determined Presentation&amp;quot; text in the table&lt;br /&gt;
    with the presentation name __EXACTLY__ as it is on the presentation page.&lt;br /&gt;
  - Replace the &amp;quot;To Be Determined&amp;quot; text in the table&lt;br /&gt;
    with the speaker(s) name(s) __EXACTLY__ as it is on the bio page.&lt;br /&gt;
  &lt;br /&gt;
3) Clean up whatever needs cleaning up.&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------- --&amp;gt;&lt;br /&gt;
{| style=&amp;quot;width:80%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#7B8ABD; color:white&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
&amp;lt;h2&amp;gt;Saturday, November 20&amp;lt;/h2&amp;gt; &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#9BA8CF&amp;quot; align=&amp;quot;center&amp;quot; | 8:00-9:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#D2D2D2&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size: 120%;&amp;quot;&amp;gt;&lt;br /&gt;
'''Breakfast and Registration'''&amp;lt;br/&amp;gt;&lt;br /&gt;
provided by our Platinum Sponsor:&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
{| border=&amp;quot;1&amp;quot;&lt;br /&gt;
| [[File:Rapid7LogoSmall.png|300px|link=http://www.rapid7.com|Rapid7]]&lt;br /&gt;
|}&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 09:00-09:50 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#B0B0B0;&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Keynote|To Be Determined Presentation|Josh Corman}}&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#9BA8CF&amp;quot; | || align=&amp;quot;center&amp;quot; style=&amp;quot;width:30%; background:#CFA49B&amp;quot; | '''Track 1'''&amp;lt;br/&amp;gt;Horace Mann Room&lt;br /&gt;
 | align=&amp;quot;center&amp;quot; style=&amp;quot;width:30%; background:#DFC799;&amp;quot; | '''Track 2'''&amp;lt;br/&amp;gt;Deborah Sampson / Paul Thomas Room&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 10:00-10:50 || style=&amp;quot;width:30%; background:#BC857A&amp;quot; align=&amp;quot;center&amp;quot; |  &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|HTML5 Security|Ming Chow}}&lt;br /&gt;
 | style=&amp;quot;width:30%; background:#BCA57A&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|OWASP Basics 1 and 2|Robert Cheyne}}&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#9BA8CF&amp;quot; align=&amp;quot;center&amp;quot; | 11:00-11:50 || style=&amp;quot;width:30%; background:#CFA49B&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|A Crumple Zone for Service Oriented Architectures|Andrew Gronosky}}&lt;br /&gt;
 | style=&amp;quot;width:30%; background:#DFC799&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
{{2010_BASC:Presentaton_Agenda_Template|Presentation|OWASP Basics 1 and 2|Robert Cheyne}}&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 12:00-13:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
'''Lunch provided by our platinum sponsor'''&lt;br /&gt;
{| border=&amp;quot;1&amp;quot;&lt;br /&gt;
|[[File:SI-Banner-238x57.jpg|link=http://www.securityinnovation.com|Security Innovation]]&lt;br /&gt;
|}&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 13:00-13:50 || style=&amp;quot;width:30%; background:#BC857A&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
'''[[Link to Preso Page | Track 1 Preso 3]]''' &amp;lt;br&amp;gt;&lt;br /&gt;
''[http://authorurl.com Author Name]''&amp;lt;br&amp;gt;&lt;br /&gt;
[http://video.google.com/ VIDEO] / [http://owasp.org SLIDES]&lt;br /&gt;
&lt;br /&gt;
 | style=&amp;quot;width:30%; background:#BCA57A&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
'''[[Link to Preso Page | Track 2 Preso 3]]''' &amp;lt;br&amp;gt;&lt;br /&gt;
''[http://authorurl.com Author Name]''&amp;lt;br&amp;gt;&lt;br /&gt;
[http://video.google.com/ VIDEO] / [http://owasp.org SLIDES]&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 14:00-14:50 || style=&amp;quot;width:30%; background:#CFA49B&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
'''[[Link to Preso Page | Track 1 Preso 4]]''' &amp;lt;br&amp;gt;&lt;br /&gt;
''[http://authorurl.com Author Name]''&amp;lt;br&amp;gt;&lt;br /&gt;
[http://video.google.com/ VIDEO] / [http://owasp.org SLIDES]&lt;br /&gt;
&lt;br /&gt;
 | style=&amp;quot;width:30%; background:#DFC799&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
'''[[Link to Preso Page | Track 2 Preso 4]]''' &amp;lt;br&amp;gt;&lt;br /&gt;
''[http://authorurl.com Author Name]''&amp;lt;br&amp;gt;&lt;br /&gt;
[http://video.google.com/ VIDEO] / [http://owasp.org SLIDES]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 15:00-15:50 || style=&amp;quot;width:30%; background:#BC857A&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
'''[[Link to Preso Page | Track 1 Preso 5]]''' &amp;lt;br&amp;gt;&lt;br /&gt;
''[http://authorurl.com Author Name]''&amp;lt;br&amp;gt;&lt;br /&gt;
[http://video.google.com/ VIDEO] / [http://owasp.org SLIDES]&lt;br /&gt;
&lt;br /&gt;
 | style=&amp;quot;width:30%; background:#BCA57A&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
'''[[Link to Preso Page | Track 2 Preso 5]]''' &amp;lt;br&amp;gt;&lt;br /&gt;
''[http://authorurl.com Author Name]''&amp;lt;br&amp;gt;&lt;br /&gt;
[http://video.google.com/ VIDEO] / [http://owasp.org SLIDES]&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 16:00-16:50 || style=&amp;quot;width:30%; background:#CFA49B&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
'''[[Link to Preso Page | Track 1 Preso 6]]''' &amp;lt;br&amp;gt;&lt;br /&gt;
''[http://authorurl.com Author Name]''&amp;lt;br&amp;gt;&lt;br /&gt;
[http://video.google.com/ VIDEO] / [http://owasp.org SLIDES]&lt;br /&gt;
&lt;br /&gt;
 | style=&amp;quot;width:30%; background:#DFC799&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
'''[[Link to Preso Page | Track 2 Preso 6]]''' &amp;lt;br&amp;gt;&lt;br /&gt;
''[http://authorurl.com Author Name]''&amp;lt;br&amp;gt;&lt;br /&gt;
[http://video.google.com/ VIDEO] / [http://owasp.org SLIDES]&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 17:00-17:30 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:30%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
'''Social Time provided by our platinum sponsor'''&lt;br /&gt;
{| border=&amp;quot;1&amp;quot;&lt;br /&gt;
| [[File:boston-2010-source-277x70.jpg|link=http://www.sourceconference.com|SOURCE]]&lt;br /&gt;
|}&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 17:30-18:30 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:30%; background:#D2D2D2&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
'''Expert Panel:'''&amp;lt;br&amp;gt;&lt;br /&gt;
''[http://authorurl.com Presenter Name] Company &amp;amp; Title, &amp;lt;br&amp;gt;&lt;br /&gt;
[http://authorurl.com Presenter Name] Company &amp;amp; Title, &amp;lt;br&amp;gt;&lt;br /&gt;
[http://authorurl.com Presenter Name] Company &amp;amp; Title, &amp;lt;br&amp;gt;&lt;br /&gt;
[http://authorurl.com Presenter Name] Company &amp;amp; Title, &amp;lt;br&amp;gt;&lt;br /&gt;
[http://authorurl.com Presenter Name] Company &amp;amp; Title, &amp;lt;br&amp;gt;&lt;br /&gt;
[http://authorurl.com Presenter Name] Company &amp;amp; Title, &amp;lt;br&amp;gt;&lt;br /&gt;
Moderator: [http://authorurl.com   Moderator Name]''&amp;lt;br&amp;gt;&lt;br /&gt;
[http://video.google.com/ VIDEO] / [http://owasp.org SLIDES]&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 18:30-19:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:30%; background:#99FF99&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
'''Wrap Up'''&amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
{{2010_BASC:WIP_Template}}&lt;br /&gt;
{{2010_BASC:Footer_Template | Agenda}}&lt;/div&gt;</summary>
		<author><name>Mark A. Arnold</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=2010_BASC_Sponsors&amp;diff=92018</id>
		<title>2010 BASC Sponsors</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=2010_BASC_Sponsors&amp;diff=92018"/>
				<updated>2010-10-27T03:32:27Z</updated>
		
		<summary type="html">&lt;p&gt;Mark A. Arnold: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;&amp;lt;div style=&amp;quot;font-size:110%; font-weight:bold;&amp;quot;&amp;gt;&lt;br /&gt;
We kindly thank our [[2010 BASC Sponsors|sponsors]] for their support. Please help us keep future BASCs free by visiting our sponsors.&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;/div&amp;gt;&amp;lt;/center&amp;gt;&lt;br /&gt;
== Platinum Sponsors (Listed Alphabetically) ==&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
[[File:Rapid7LogoLarge.png|alt=Rapid7|link=http://Rapid7.com|Rapid7]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:150%&amp;quot;&amp;gt;Visit [http://rapid7.com Rapid7]&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
[[File:Safelight_logo_large.gif|alt=SafeLight Logo|link=http://safelightsecurity.com|SafeLight Security Advisors]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:150%&amp;quot;&amp;gt;Visit [http://safelightsecurity.com SafeLight Security Advisors].&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
[[File:SI-Banner-755x160-v2.jpg|alt=Security Innovation Logo|link=http://securityinnovation.com|Security Innovation]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:150%&amp;quot;&amp;gt;Visit [http://securityinnovation.com Security Innovation].&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
[[File:2010_BASC_SponsorLogo-755x160.png|alt=Platinum Sponsor Banner Logo|link=2010_BASC_Request_For_Sponsors|Be A Sponsor]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:150%&amp;quot;&amp;gt;Only GOLD Slots Left. Visit [[2010_BASC_Request_For_Sponsors|Our Request For Sponsors]] Page For More Info.&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;/center&amp;gt;&lt;br /&gt;
== Gold Sponsors (Listed Alphabetically) ==&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
[[File:Whitehatlogo-medium.png|link=http://www.whitehatsec.com|WhiteHat Security]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:150%&amp;quot;&amp;gt;Visit [http://whitehatsec.com WhiteHat Security]&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
[[File:2010_BASC_SponsorLogo-290x60.png|link=2010_BASC_Request_For_Sponsors|Be A Sponsor]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:150%&amp;quot;&amp;gt;Interested? Visit [[2010_BASC_Request_For_Sponsors|Our Request For Sponsors]]&amp;lt;br/&amp;gt;&lt;br /&gt;
Page For More Info.&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;/center&amp;gt;&lt;br /&gt;
{{2010_BASC:Footer_Template | Sponsors}}&lt;/div&gt;</summary>
		<author><name>Mark A. Arnold</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=2010_BASC_Request_For_Sponsors&amp;diff=90470</id>
		<title>2010 BASC Request For Sponsors</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=2010_BASC_Request_For_Sponsors&amp;diff=90470"/>
				<updated>2010-10-01T14:28:55Z</updated>
		
		<summary type="html">&lt;p&gt;Mark A. Arnold: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{2010_BASC:Header_Template | Request for Sponsors}}&lt;br /&gt;
&lt;br /&gt;
On November 20, 2010 '''[[Boston|OWASP Boston]]''' launches the inaugural '''Boston Application Security Conference 2010''' ([[2010 BASC Homepage|2010 BASC]]) to take place at Microsoft New England Research and Development Center ([http://microsoftcambridge.com/Default.aspx NERD]) in Cambridge, MA. The BASC is a one day, informal conference, aimed at increasing awareness and knowledge of application security. Many of the presentations will cover state-of-the-art application security concepts. The BASC is intended to appeal to a wide-array of attendees and is expected to attract over 150 attendees. Application security professionals, professional software developers, software quality engineers, computer science students, and security software vendors should be able to come to the BASC, learn, and hopefully enjoy themselves at the same time expand upon their application security knowledge and become better application security practitioners. We are pleased to announce that '''[http://www.the451group.com/about/bio_detail.php?eid=407 Josh Corman]''', renown 451 Group Security Analyst and evangelist and co-founder of [http://www.ruggedsoftware.org/ Rugged Software] is our confirmed keynote speaker for the [[2010 BASC Homepage|2010 BASC]].&lt;br /&gt;
&lt;br /&gt;
We invite potential sponsors to partner with us on two levels: $700.00 PLATINUM Level and $500.00 GOLD level. Gold level sponsorship includes a standard logo listing in program guide and event site and a table. We are seeking three Platinum sponsors to cover breakfast, lunch times and “happy hour” timeslots. Platinum sponsors benefits include premium signage (large logo listing in program and event site), table and additional credit/special mention in our program guide. There are 8 maximum sponsorships in all. '''''OWASP Boston’s non-profit status means all sponsorships are tax-deductible. OWASP Boston is a 501(c)(3) organization.''''' An extra benefit for sponsors is  permanent brand presence on the BASC website alongside slides and, in some cases, video links of the conference presentation. Post-conference traffic to the BASC site means continued exposure for our sponsors.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt;&amp;lt;div style=&amp;quot;border: 3px solid #EEEEEE; font-size:130%;&amp;quot;&amp;gt;'''Note'''&amp;lt;br&amp;gt;&lt;br /&gt;
The [[2010 BASC Homepage|2010 BASC]] can have a maximum of three platinum sponsors.&amp;lt;br/&amp;gt;&lt;br /&gt;
'''Two have been filled. Only one platinum sponsorship remains.'''&lt;br /&gt;
See current [[2010 BASC Sponsors]].&amp;lt;/div&amp;gt;&amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
If you wish to sponsor this event or get more information about being a sponsor, please feel free to [mailto:basc-sponsors@onestopappsecurity.com email us]. 25% of all sponsorships monies go to supporting [http://owasp.org OWASP.org]. As you consider sponsorship of  BASC 2010, we encourage you to  become corporate member (if not one currently) of OWASP  to further the organization’s efforts to improve the global application security landscape.&lt;br /&gt;
&lt;br /&gt;
== Sponsorship Logo Privileges ==&lt;br /&gt;
Gold Sponsors get a logo on the [[2010 BASC Sponsors]] page of the BASC website as well as printed icons at various locations and on handouts at the conference. For the website, the logo should be about 17.5K pixels. This can be a 132x132 square logo or a 290x60 rectangular logo.&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&amp;lt;center&amp;gt;&lt;br /&gt;
[[File:2010_BASC_SponsorLogo-132x132.png|link=2010_BASC_Request_For_Sponsors|132x132]]&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
[[File:2010_BASC_SponsorLogo-290x60.png|link=2010_BASC_Request_For_Sponsors|290x60]]&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&amp;lt;/center&amp;gt;&lt;br /&gt;
We will be happy to work with other shapes in the same general size.&lt;br /&gt;
&lt;br /&gt;
Platinum sponsors get a logo of the above dimensions at the top of every page of the BASC website. They also get a banner logo of about 755x160 pixels.&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&amp;lt;center&amp;gt;&lt;br /&gt;
[[File:2010_BASC_SponsorLogo-755x160.png|link=2010_BASC_Request_For_Sponsors|755x160]]&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&amp;lt;/center&amp;gt;&lt;br /&gt;
Platinum sponsors will get printed icons at prime locations and of larger size at various locations and on handouts at the conference. Each platinum sponsor will also be credited as sponsoring one of the [[2010 BASC Agenda|three food events]] during the conference.&lt;br /&gt;
&lt;br /&gt;
{{2010_BASC:Footer_Template | Sponsors}}&lt;/div&gt;</summary>
		<author><name>Mark A. Arnold</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Template:2010_BASC:Sponsor_Bar_Template&amp;diff=90469</id>
		<title>Template:2010 BASC:Sponsor Bar Template</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Template:2010_BASC:Sponsor_Bar_Template&amp;diff=90469"/>
				<updated>2010-10-01T14:23:52Z</updated>
		
		<summary type="html">&lt;p&gt;Mark A. Arnold: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;border:3px solid #EEEEEE;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:130%; font-weight:bold;&amp;quot;&amp;gt;Platinum Sponsors (Listed Alphabetically)&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;table width=&amp;quot;100%&amp;quot;&amp;gt;&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td width=&amp;quot;33%&amp;quot;&amp;gt;[[File:Rapid7LogoSmall.png|link=http://www.rapid7.com|Rapid7]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td width=&amp;quot;33%&amp;quot;&amp;gt;[[File:SI-Banner-238x57.jpg|link=http://www.securityinnovation.com|Security Innovation]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td width=&amp;quot;33%&amp;quot;&amp;gt;[[File:2010_BASC_SponsorLogo-290x60.png|link=2010_BASC_Request_For_Sponsors|Request For Sponsors]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&amp;lt;/table&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:110%; font-weight:bold;&amp;quot;&amp;gt;&lt;br /&gt;
We kindly thank our sponsors for their support. Please help us keep future BASCs free by viewing and visiting [[2010 BASC Sponsors|all of our sponsors]].&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;/center&amp;gt;&lt;/div&gt;</summary>
		<author><name>Mark A. Arnold</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=2010_BASC_Homepage&amp;diff=89514</id>
		<title>2010 BASC Homepage</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=2010_BASC_Homepage&amp;diff=89514"/>
				<updated>2010-09-17T20:04:39Z</updated>
		
		<summary type="html">&lt;p&gt;Mark A. Arnold: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{2010_BASC:Header_Template | Welcome}}&lt;br /&gt;
This is the homepage for the 2010 Boston Application Security Conference (BASC). This free conference will take place on Saturday, November 20&amp;lt;sup&amp;gt;th&amp;lt;/sup&amp;gt; at [http://microsoftcambridge.com/Default.aspx Microsoft New England Research and Development Center (NERD)].&lt;br /&gt;
&lt;br /&gt;
The BASC will be a free, one day, informal conference, aimed at increasing awareness and knowledge of application security in the greater Boston area. While many of the presentations will cover state-of-the-art application security concepts, the BASC is intended to appeal to a wide-array of attendees. Application security professionals, professional software developers, software quality engineers, computer science students, and security software vendors should be able to come to the BASC, learn, and hopefully enjoy themselves at the same time.&lt;br /&gt;
&lt;br /&gt;
== The Details ==&lt;br /&gt;
* Date: Saturday, November 20&amp;lt;sup&amp;gt;th&amp;lt;/sup&amp;gt;, 2010&lt;br /&gt;
* Time: 8:00 AM - 5:30 PM&lt;br /&gt;
* Location: [http://microsoftcambridge.com/Default.aspx NERD]&lt;br /&gt;
* Directions: [http://microsoftcambridge.com/About/Directions/tabid/89/Default.aspx NERD's website] or [http://maps.google.com/places/us/ma/cambridge/memorial-dr/1/-microsoft-new-england-research-and-development-center?hl=en&amp;amp;gl=us Google Maps]&lt;br /&gt;
* Registration: [http://basc2010.eventbrite.com/ Online registration]&lt;br /&gt;
* Agenda: [[2010_BASC_Agenda | Agenda]] (a work in progress)&lt;br /&gt;
* Call for papers: [[2010_BASC_Call_For_Papers | 2010 BASC CALL FOR PAPERS]]&lt;br /&gt;
&lt;br /&gt;
== Registration ==&lt;br /&gt;
Admission to the BASC is free but registration is required for breakfast, lunch, and the evening social time. We will do everything possible to accommodate late registrants but the facility and food are limited. [http://basc2010.eventbrite.com/ Online registration] is now open and you are encouraged to register early.&lt;br /&gt;
&lt;br /&gt;
== Call For Papers ==&lt;br /&gt;
We are accepting presentation proposals until October 10&amp;lt;sup&amp;gt;th&amp;lt;/sup&amp;gt;. If If you are interested in being a presenter at the 2010 BASC, you can read the complete [[2010_BASC_Call_For_Papers | 2010 BASC CALL FOR PAPERS]].&lt;br /&gt;
&lt;br /&gt;
== Request for Sponsors ==&lt;br /&gt;
We are soliciting sponsorship for BASC 2010. If If you are interested in being a sponsor, see the detailed request for [[2010_BASC_Sponsors | 2010 BASC REQUEST FOR SPONSORS]].&lt;br /&gt;
&lt;br /&gt;
{{2010_BASC:Footer_Template | Welcome}}&lt;/div&gt;</summary>
		<author><name>Mark A. Arnold</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=2010_BASC_Request_For_Sponsors&amp;diff=89510</id>
		<title>2010 BASC Request For Sponsors</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=2010_BASC_Request_For_Sponsors&amp;diff=89510"/>
				<updated>2010-09-17T18:13:33Z</updated>
		
		<summary type="html">&lt;p&gt;Mark A. Arnold: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{2010_BASC:Header_Template | Request for Sponsors}}&lt;br /&gt;
&lt;br /&gt;
On November 20, 2010 '''OWASP Boston''' (http://www.owasp.org/index.php/Boston) launches the inaugural '''Boston Application Security Conference 2010''' (BASC 2010) (http://www.owasp.org/index.php/Boston_Application_Security_Conference) to take place Microsoft  New England Research and Development Center (NERD http://microsoftcambridge.com/Default.aspx) in Cambridge, MA. The BASC will is a one day, informal conference, aimed at increasing awareness and knowledge of application security. Many of the presentations will cover state-of-the-art application security concepts. The BASC is intended to appeal to a wide-array of attendees and is expected to attract over 150 attendees. Application security professionals, professional software developers, software quality engineers, computer science students, and security software vendors should be able to come to the BASC, learn, and hopefully enjoy themselves at the same time expand upon their application security knowledge and become better application security practitioners. We are pleased to announce that '''Josh Corman''' (http://www.the451group.com/about/bio_detail.php?eid=407), renown 451 Group Security Analyst and evangelist and co-founder of “Rugged Software” (http://www.ruggedsoftware.org/) is our confirmed keynote speaker for BASC 2010. &lt;br /&gt;
&lt;br /&gt;
We invite potential sponsors to partner with us on two levels: 700.00 PLATINUM Level and 500.00 GOLD level. Gold level sponsorship includes a standard logo listing in program guide and event site and a table. We are seeking three Platinum sponsors to cover breakfast, lunch times and “happy hour” timeslots. Platinum sponsors benefits include premium signage (large logo listing in program and event site), table and additional credit/special mention in our program guide. There are 8 maximum sponsorships in all. '''''OWASP Boston’s non-profit status means all sponsorships are tax-deductible. OWASP Boston is a 501(c)(3) organization.''''' An extra benefit for sponsors is  permanent brand presence on the BASC website alongside slides (and video) links of the conference presentation. Post conference traffic to the BASC site means continued exposure for our sponsors. &lt;br /&gt;
&lt;br /&gt;
Please affirm your desire to be a part of BASC 2010 in this capacity by replying to this communication. We will contact you in return to discuss the sponsorship process further. 25% of all sponsorships monies to support OWASP.org. As you consider sponsorship of  BASC 2010, we encourage you to  become corporate member (if not one currently) of OWASP  to further the organization’s efforts to improve the global application security landscape.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{{2010_BASC:Footer_Template | Sponsors}}&lt;/div&gt;</summary>
		<author><name>Mark A. Arnold</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=2010_BASC_Request_For_Sponsors&amp;diff=89509</id>
		<title>2010 BASC Request For Sponsors</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=2010_BASC_Request_For_Sponsors&amp;diff=89509"/>
				<updated>2010-09-17T18:09:08Z</updated>
		
		<summary type="html">&lt;p&gt;Mark A. Arnold: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{2010_BASC:Header_Template | Request for Sponsors}}&lt;br /&gt;
&lt;br /&gt;
On November 20, 2010 OWASP Boston (http://www.owasp.org/index.php/Boston) launches the inaugural Boston Application Security Conference 2010 (BASC 2010) (http://www.owasp.org/index.php/Boston_Application_Security_Conference) to take place Microsoft  New England Research and Development Center (NERD http://microsoftcambridge.com/Default.aspx) in Cambridge, MA. The BASC will is a one day, informal conference, aimed at increasing awareness and knowledge of application security. Many of the presentations will cover state-of-the-art application security concepts. The BASC is intended to appeal to a wide-array of attendees and is expected to attract over 150 attendees. Application security professionals, professional software developers, software quality engineers, computer science students, and security software vendors should be able to come to the BASC, learn, and hopefully enjoy themselves at the same time expand upon their application security knowledge and become better application security practitioners. We are pleased to announce that Josh Corman (http://www.the451group.com/about/bio_detail.php?eid=407), renown 451 Group Security Analyst and evangelist and co-founder of “Rugged Software” (http://www.ruggedsoftware.org/) is our confirmed keynote speaker for BASC 2010. &lt;br /&gt;
&lt;br /&gt;
We invite potential sponsors to partner with us on two levels: 700.00 PLATINUM Level and 500.00 GOLD level. Gold level sponsorship includes a standard logo listing in program guide and event site and a table. We are seeking three Platinum sponsors to cover breakfast, lunch times and “happy hour” timeslots. Platinum sponsors benefits include premium signage (large logo listing in program and event site), table and additional credit/special mention in our program guide. There are 8 maximum sponsorships in all. OWASP Boston’s non-profit status means all sponsorships are tax-deductible. OWASP Boston is a 501(c)(3) organization. An extra benefit for sponsors is  permanent brand presence on the BASC website alongside slides (and video) links of the conference presentation. Post conference traffic to the BASC site means continued exposure for our sponsors. &lt;br /&gt;
&lt;br /&gt;
Please affirm your desire to be a part of BASC 2010 in this capacity by replying to this communication. We will contact you in return to discuss the sponsorship process further. 25% of all sponsorships monies to support OWASP.org. As you consider sponsorship of  BASC 2010, we encourage you to  become corporate member (if not one currently) of OWASP  to further the organization’s efforts to improve the global application security landscape.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{{2010_BASC:Footer_Template | Sponsors}}&lt;/div&gt;</summary>
		<author><name>Mark A. Arnold</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=2010_BASC_Request_For_Sponsors&amp;diff=89508</id>
		<title>2010 BASC Request For Sponsors</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=2010_BASC_Request_For_Sponsors&amp;diff=89508"/>
				<updated>2010-09-17T18:01:12Z</updated>
		
		<summary type="html">&lt;p&gt;Mark A. Arnold: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{2010_BASC:Header_Template | Sponsors}}&lt;br /&gt;
&lt;br /&gt;
On November 20, 2010 OWASP Boston (http://www.owasp.org/index.php/Boston) launches the inaugural Boston Application Security Conference 2010 (BASC 2010) (http://www.owasp.org/index.php/Boston_Application_Security_Conference) to take place Microsoft  New England Research and Development Center (NERD http://microsoftcambridge.com/Default.aspx) in Cambridge, MA. The BASC will is a one day, informal conference, aimed at increasing awareness and knowledge of application security. Many of the presentations will cover state-of-the-art application security concepts. The BASC is intended to appeal to a wide-array of attendees and is expected to attract over 150 attendees. Application security professionals, professional software developers, software quality engineers, computer science students, and security software vendors should be able to come to the BASC, learn, and hopefully enjoy themselves at the same time expand upon their application security knowledge and become better application security practitioners. We are pleased to announce that Josh Corman (http://www.the451group.com/about/bio_detail.php?eid=407), renown 451 Group Security Analyst and evangelist and co-founder of “Rugged Software” (http://www.ruggedsoftware.org/) is our confirmed keynote speaker for BASC 2010. &lt;br /&gt;
&lt;br /&gt;
We invite potential sponsors to partner with us on two levels: 700.00 PLATINUM Level and 500.00 GOLD level. Gold level sponsorship includes a standard logo listing in program guide and event site and a table. We are seeking three Platinum sponsors to cover breakfast, lunch times and “happy hour” timeslots. Platinum sponsors benefits include premium signage (large logo listing in program and event site), table and additional credit/special mention in our program guide. There are 8 maximum sponsorships in all. OWASP Boston’s non-profit status means all sponsorships are tax-deductible. OWASP Boston is a 501(c)(3) organization. An extra benefit for sponsors is  permanent brand presence on the BASC website alongside slides (and video) links of the conference presentation. Post conference traffic to the BASC site means continued exposure for our sponsors. &lt;br /&gt;
&lt;br /&gt;
Please affirm your desire to be a part of BASC 2010 in this capacity by replying to this communication. We will contact you in return to discuss the sponsorship process further. 25% of all sponsorships monies to support OWASP.org. As you consider sponsorship of  BASC 2010, we encourage you to  become corporate member (if not one currently) of OWASP  to further the organization’s efforts to improve the global application security landscape.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{{2010_BASC:Footer_Template | Sponsors}}&lt;/div&gt;</summary>
		<author><name>Mark A. Arnold</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=2010_BASC_Request_For_Sponsors&amp;diff=89507</id>
		<title>2010 BASC Request For Sponsors</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=2010_BASC_Request_For_Sponsors&amp;diff=89507"/>
				<updated>2010-09-17T17:57:38Z</updated>
		
		<summary type="html">&lt;p&gt;Mark A. Arnold: Stock Request for Sponsorship for BASC 2010&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{2010_BASC:Header_Template | Sponsors}}&lt;br /&gt;
{{2010_BASC:WIP_Template}}&lt;br /&gt;
On November 20, 2010 OWASP Boston (http://www.owasp.org/index.php/Boston) launches the inaugural Boston Application Security Conference 2010 (BASC 2010) (http://www.owasp.org/index.php/Boston_Application_Security_Conference) to take place Microsoft  New England Research and Development Center (NERD http://microsoftcambridge.com/Default.aspx) in Cambridge, MA. The BASC will is a one day, informal conference, aimed at increasing awareness and knowledge of application security. Many of the presentations will cover state-of-the-art application security concepts. The BASC is intended to appeal to a wide-array of attendees and is expected to attract over 150 attendees. Application security professionals, professional software developers, software quality engineers, computer science students, and security software vendors should be able to come to the BASC, learn, and hopefully enjoy themselves at the same time expand upon their application security knowledge and become better application security practitioners. We are pleased to announce that Josh Corman (http://www.the451group.com/about/bio_detail.php?eid=407), renown 451 Group Security Analyst and evangelist and co-founder of “Rugged Software” (http://www.ruggedsoftware.org/) is our confirmed keynote speaker for BASC 2010. &lt;br /&gt;
&lt;br /&gt;
We invite potential sponsors to partner with us on two levels: 700.00 PLATINUM Level and 500.00 GOLD level. Gold level sponsorship includes a standard logo listing in program guide and event site and a table. We are seeking three Platinum sponsors to cover breakfast, lunch times and “happy hour” timeslots. Platinum sponsors benefits include premium signage (large logo listing in program and event site), table and additional credit/special mention in our program guide. There are 8 maximum sponsorships in all. OWASP Boston’s non-profit status means all sponsorships are tax-deductible. OWASP Boston is a 501(c)(3) organization. An extra benefit for sponsors is  permanent brand presence on the BASC website alongside slides (and video) links of the conference presentation. Post conference traffic to the BASC site means continued exposure for our sponsors. &lt;br /&gt;
&lt;br /&gt;
Please affirm your desire to be a part of BASC 2010 in this capacity by replying to this communication. We will contact you in return to discuss the sponsorship process further. 25% of all sponsorships monies to support OWASP.org. As you consider sponsorship of  BASC 2010, we encourage you to  become corporate member (if not one currently) of OWASP  to further the organization’s efforts to improve the global application security landscape.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{{2010_BASC:WIP_Template}}&lt;br /&gt;
{{2010_BASC:Footer_Template | Sponsors}}&lt;/div&gt;</summary>
		<author><name>Mark A. Arnold</name></author>	</entry>

	</feed>